Skip to content

LPA Crypto Heart

This content is for v1.0. Switch to the latest version for up-to-date documentation.

Know policy bundles were not tampered with between compile and load — signed artifacts, published hashes, and heartbeats that tie runtime units to declared intent.

  • Supply-chain for policy — OPA bundles signed before fabric units load them
  • Provenance — heartbeats link a running PEP to a known policy generation
  • Pairs with CALM Forge — compiled intent becomes verifiable runtime state
CALM Forge (compile) → signed bundle (LPA) → Starfly unit verifies hash → loads policy
heartbeats → graph / audit

Exchange and revocation do not wait on signing — verification happens at bundle load and on schedule.

Preview — LPA crypto heart export pending in this repository.

Code stub: lpa-crypto-heart/