The data boundary is part of the product design. Signing requests contain commitment hashes and execution metadata, not the underlying content being governed.
Primust stores standard account information, authentication state, billing records, and service telemetry needed to operate the dashboard and API. That is separate from governed content.
Signing requests contain commitment hashes and related execution metadata. By default, signing metadata is retained for 90 days for service operation, abuse prevention, and support.
A relying party can verify issuer, signature, proof level, bundles, and declared gaps with the open-source verifier and Primust public keys. Verification does not require calling Primust.
Public verification keys are published through the Primust well-known key endpoint. That lets counterparties validate a credential independently and archive the trust material they rely on.
The marketing site uses Vercel Analytics and Vercel Speed Insights to measure page traffic and page performance. Those scripts are limited to the public website. They are not part of the dashboard, API, signing flow, or offline verification flow.
Primust does not use business-visitor identification on the marketing site, and the verifier does not depend on Primust analytics infrastructure.
The strongest trust claim on the site should be one you can test yourself.