Vendor sign-off

Countersign vendor sign-off summary

This one-page summary is for security, procurement, or vendor-review teams assessing whether Countersign can receive redacted CI/CD configuration for a fixed-price review.

Service scope

Countersign provides async, fixed-price CI/CD pipeline configuration reviews. The reviewer reads submitted configuration, identifies ranked risks, and returns a human-signed verdict with dated references and concrete remediation guidance.

Countersign does not require repository access, account access, source-code access, production credentials, or an installed agent.

Data handling commitments

Accepted material
CI/CD configuration only. Secrets, credentials, private keys, and tokens are out of scope and should be redacted before submission.
Secret rejection
Likely secrets are rejected before storage. Buyers can redact and resubmit while preserving structural context.
Storage
Submitted configuration is encrypted at rest with libsodium secretbox. The encryption key is kept outside the public web path.
Retention
Submitted config is hard-deleted at the earlier of 14 days after submission or 7 days after verdict delivery.
Receipts and notices
Notices and deletion receipts are metadata-only; submitted config and secrets are not emailed back.

Review boundaries

  • Submitted config is reviewed by the Countersign operator for the requested verdict.
  • Submitted config is not routed to subcontracted reviewers, analytics tools, or model vendors for review.
  • Submitted config is never absorbed into a product dataset, trained on, resold, shared, or published without explicit de-identification approval.
  • Operational hosting and email transport support the service, but submitted config content is not used as an operational analytics or training artifact.

Approval use

This document is intended to support a low-friction vendor review for a configuration-only, no-repository-access service. Organizations with stricter procurement requirements may also review the optional mutual NDA artifact.

Current as of 2026-06-09. Canonical public terms: countersign.dev/trust/