Trust Center
Encryption evidence
How to review protection for a specific Lithi data path without treating one algorithm or service statement as universal proof.
On this page
Encryption should be reviewed for a specific data category and path: on a customer device, while moving between systems, inside a service, in backups, and at any provider boundary. A library, configuration, algorithm name, or supplier statement does not prove that every Lithi path uses the same protection. Current evidence should identify the product, environment, key owner, data state, service, and review period.
What this means for you
Name the data you need to protect and follow it through the complete workflow. Ask when it is encrypted, where keys are controlled, which identities can request access, how rotation or revocation is handled, and which exceptions exist. Keep customer-controlled device storage, service storage, connection processing, logging, support material, and backups separate.
For procurement, request evidence tied to the exact environment you will use. Match a control description with a dated test or service record rather than treating a general architecture statement as a complete guarantee.
Where plaintext may exist during execution
Lithi uses encrypted transport on approved network paths and signed envelopes where the current protocol requires them. That protects a task in transit; it is not the same as the executing environment.
The Mac that performs Compute work still has to process the task, which means the task exists as ordinary, unencrypted data in that Mac's memory while it runs. A participating provider Mac is not a confidential-computing enclave, and Lithi does not claim otherwise. Provider-facing Lithi surfaces are designed to stay blind to customer content, but a privileged owner with physical or root-level access to that Mac may still be able to inspect ordinary unified memory during execution. Review this boundary against the exact data category and sensitivity of the work you send.
What this review covers
| Field | Record |
|---|---|
| Scope | One named product, data category, state, service, key owner, and environment. |
| Status | Review guidance; universal encryption coverage is not established here. |
| Owner | Lithi trust team |
| Evidence | Current control material and path-specific protection evidence. |
| Last reviewed | 2026-09-03 |
| Limitation | This page does not prove algorithms, key location, rotation, backups, logs, or provider behavior. |
Limits
Different paths can use different controls, and protection can change across versions, providers, and customer configurations. Encryption does not by itself prove identity, authorization, tenant separation, retention, deletion, or recovery. Any unresolved question should name the path and required evidence.
Primary action
Request scoped encryption evidence