{"id":45761638,"url":"https://github.com/tang-edge/tang-edge","last_synced_at":"2026-03-04T05:00:56.676Z","repository":{"id":340657355,"uuid":"1166619252","full_name":"tang-edge/tang-edge","owner":"tang-edge","description":"Serverless Tang server for disk encryption key recovery — deploy to Cloudflare, AWS, GCP, Azure, Deno, Vercel, Netlify, Supabase","archived":false,"fork":false,"pushed_at":"2026-02-25T23:25:16.000Z","size":365,"stargazers_count":5,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-02-27T03:58:04.452Z","etag":null,"topics":["clevis","cloudflare-workers","cryptography","disk-encryption","edge-computing","hono","key-management","luks","nbde","serverless","split-trust","tang","typescript"],"latest_commit_sha":null,"homepage":null,"language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tang-edge.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":"GOVERNANCE.md","roadmap":"ROADMAP.md","authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-02-25T12:22:52.000Z","updated_at":"2026-02-26T19:36:19.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/tang-edge/tang-edge","commit_stats":null,"previous_names":["tang-edge/tang-edge"],"tags_count":9,"template":false,"template_full_name":null,"purl":"pkg:github/tang-edge/tang-edge","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tang-edge%2Ftang-edge","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tang-edge%2Ftang-edge/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tang-edge%2Ftang-edge/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tang-edge%2Ftang-edge/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tang-edge","download_url":"https://codeload.github.com/tang-edge/tang-edge/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tang-edge%2Ftang-edge/sbom","scorecard":{"id":1244024,"data":{"date":"2026-02-25T23:25:10Z","repo":{"name":"github.com/tang-edge/tang-edge","commit":"deb9a0fcdceb26342de8c14dfc5a48e663c66939"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":8.1,"checks":[{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/14 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":10,"reason":"all dependencies are pinned","details":["Info:  14 out of  14 GitHub-owned GitHubAction dependencies pinned","Info:  11 out of  11 third-party GitHubAction dependencies pinned","Info:   2 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"Maintained","score":0,"reason":"project was created within the last 90 days. Please review its contents carefully","details":["Warn: Repository was created within the last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:17","Info: jobLevel 'contents' permission set to 'read': .github/workflows/docker.yml:14","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/ci.yml:10","Info: found token with 'none' permissions: .github/workflows/codeql.yml:1","Info: found token with 'none' permissions: .github/workflows/docker.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/fuzz.yml:10","Info: found token with 'none' permissions: .github/workflows/release.yml:1","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:10"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":7,"reason":"badge detected: Silver","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/docker.yml:11"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Fuzzing","score":10,"reason":"project is fuzzed","details":["Info: ClusterFuzzLite integration found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU General Public License v3.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Branch-Protection","score":8,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'main'","Info: 'stale review dismissal' is required to merge on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Info: codeowner review is required on branch 'main'","Info: 'last push approval' is required to merge on branch 'main'","Info: 'up-to-date branches' is required to merge on branch 'main'","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":10,"reason":"5 out of the last 5 releases have a total of 10 signed artifacts.","details":["Info: signed release artifact: tang-edge-v0.2.6.tar.gz.sigstore.json: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.6","Info: signed release artifact: tang-edge-v0.2.5.tar.gz.sigstore.json: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.5","Info: signed release artifact: tang-edge-v0.2.4.tar.gz.sigstore.json: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.4","Info: signed release artifact: tang-edge-v0.2.3.tar.gz.sigstore.json: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.3","Info: signed release artifact: tang-edge-v0.2.2.tar.gz.sigstore.json: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.2","Info: provenance for release artifact: tang-edge-v0.2.6.tar.gz.intoto.jsonl: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.6","Info: provenance for release artifact: tang-edge-v0.2.5.tar.gz.intoto.jsonl: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.5","Info: provenance for release artifact: tang-edge-v0.2.4.tar.gz.intoto.jsonl: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.4","Info: provenance for release artifact: tang-edge-v0.2.3.tar.gz.intoto.jsonl: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.3","Info: provenance for release artifact: tang-edge-v0.2.2.tar.gz.intoto.jsonl: https://github.com/tang-edge/tang-edge/releases/tag/v0.2.2"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"Contributors","score":0,"reason":"project has 0 contributing companies or organizations -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}},{"name":"CI-Tests","score":10,"reason":"15 out of 15 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}}]},"last_synced_at":"2026-02-26T01:03:24.015Z","repository_id":340657355,"created_at":"2026-02-26T01:03:24.015Z","updated_at":"2026-02-26T01:03:24.015Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29922071,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-27T19:37:42.220Z","status":"ssl_error","status_checked_at":"2026-02-27T19:37:41.463Z","response_time":57,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["clevis","cloudflare-workers","cryptography","disk-encryption","edge-computing","hono","key-management","luks","nbde","serverless","split-trust","tang","typescript"],"created_at":"2026-02-25T23:14:26.639Z","updated_at":"2026-02-28T01:00:43.531Z","avatar_url":"https://github.com/tang-edge.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\r\n\u003cimg src=\"docs/imgs/logo.png\" width=\"200\" alt=\"tang-edge\"\u003e\r\n\u003ch1\u003etang-edge\u003c/h1\u003e\r\n\u003c/div\u003e\r\n\r\n[![CI](https://github.com/tang-edge/tang-edge/actions/workflows/ci.yml/badge.svg)](https://github.com/tang-edge/tang-edge/actions/workflows/ci.yml)\r\n[![CodeQL](https://github.com/tang-edge/tang-edge/actions/workflows/codeql.yml/badge.svg)](https://github.com/tang-edge/tang-edge/actions/workflows/codeql.yml)\r\n[![Codecov](https://codecov.io/gh/tang-edge/tang-edge/graph/badge.svg)](https://codecov.io/gh/tang-edge/tang-edge)\r\n[![Quality Gate](https://sonarcloud.io/api/project_badges/measure?project=tang-edge-org_tang-edge\u0026metric=alert_status)](https://sonarcloud.io/summary/new_code?id=tang-edge-org_tang-edge)\r\n[![Security Rating](https://sonarcloud.io/api/project_badges/measure?project=tang-edge-org_tang-edge\u0026metric=security_rating)](https://sonarcloud.io/summary/new_code?id=tang-edge-org_tang-edge)\r\n[![Maintainability](https://sonarcloud.io/api/project_badges/measure?project=tang-edge-org_tang-edge\u0026metric=sqale_rating)](https://sonarcloud.io/summary/new_code?id=tang-edge-org_tang-edge)\r\n[![Snyk](https://snyk.io/test/github/tang-edge/tang-edge/badge.svg)](https://snyk.io/test/github/tang-edge/tang-edge)\r\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/tang-edge/tang-edge/badge)](https://scorecard.dev/viewer/?uri=github.com/tang-edge/tang-edge)\r\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/12036/badge?level=silver)](https://www.bestpractices.dev/projects/12036)\r\n[![Platforms](https://img.shields.io/badge/platforms-9-brightgreen)]()\r\n\r\nTang server for serverless/edge platforms. Deploy across multiple free providers and use `clevis sss` to distribute trust — no single provider can decrypt your disks.\r\n\r\nFull [Tang](https://github.com/latchset/tang) protocol (P-521 ECMR) in TypeScript, compatible with standard `clevis` clients for automatic disk encryption unlock.\r\n\r\n## Why\r\n\r\nOriginal [tang](https://github.com/latchset/tang) runs on a server you maintain. tang-edge runs on free serverless — zero ops, no VPS, no patching.\r\n\r\nThe real power is **Split Trust**: deploy tang-edge to 2-3 different providers, use `clevis sss` with a threshold. No single provider can decrypt. Physical theft + cloud compromise both needed. Free.\r\n\r\n### Comparison\r\n\r\n| | tang-edge | [tang](https://github.com/latchset/tang) (original) | AWS KMS / Vault |\r\n|---|-----------|------------------------------------------------------|-----------------|\r\n| Infrastructure | None (serverless free tier) | VPS / bare metal | Managed service |\r\n| Ops burden | Zero — no patching, no uptime | You maintain the server | Vendor manages |\r\n| Split Trust cost | Free (2-3 free edge accounts) | 2-3 VPS ($5-20/mo each) | $$$, vendor lock-in |\r\n| Kill switch | Disable worker → disk locked on next reboot | Shut down server → same | Revoke key → same |\r\n| Protocol | Standard Tang (clevis-compatible) | Standard Tang | Proprietary API |\r\n| Latency | \u003c50ms (300+ edge locations) | Depends on server location | ~100ms |\r\n| Compliance | Helps meet GDPR, HIPAA, PCI-DSS | Same | Built-in certifications |\r\n| When to use | Remote servers, homelab, NAS, VPS | On-prem with local network | Enterprise with budget |\r\n\r\n## Supported Platforms\r\n\r\n| Platform | Storage | Guide |\r\n|----------|---------|-------|\r\n| Cloudflare Workers | KV | [Deploy + WAF](docs/cloudflare.md) |\r\n| Deno Deploy | Deno KV | [Deploy](docs/deno-deploy.md) |\r\n| Vercel | Vercel KV | [Deploy](docs/vercel.md) |\r\n| AWS Lambda | DynamoDB | [Deploy + WAF](docs/aws-lambda.md) |\r\n| GCP Cloud Functions | Firestore | [Deploy + Cloud Armor](docs/gcp.md) |\r\n| Netlify Functions | Blobs | [Deploy](docs/netlify.md) |\r\n| Azure Functions | Table Storage | [Deploy + Front Door](docs/azure.md) |\r\n| Supabase Edge Functions | Postgres | [Deploy](docs/supabase.md) |\r\n| Fastly Compute | KV Store | [Deploy](docs/fastly.md) |\r\n\r\n## Quick Start\r\n\r\n```bash\r\nbash setup.sh\r\n```\r\n\r\nInteractive wizard: picks platform, installs deps, configures storage, deploys.\r\n\r\n**No local tools?** Deploy from Docker (wrangler, deployctl, vercel, netlify, supabase, fastly all included):\r\n\r\n```bash\r\ndocker run --rm -e CLOUDFLARE_API_TOKEN=$TOKEN \\\r\n  ghcr.io/tang-edge/tang-edge cloudflare\r\n```\r\n\r\nSee [Docker Deploy](docs/docker.md) for all platforms.\r\n\r\n## Split Trust (SSS)\r\n\r\nThe main use case. Deploy to 2+ providers, require all for decryption:\r\n\r\n```bash\r\nclevis luks bind -d /dev/sdX sss '{\r\n  \"t\": 2,\r\n  \"pins\": {\r\n    \"tang\": [\r\n      {\"url\": \"https://tang-edge.example.workers.dev\"},\r\n      {\"url\": \"https://tang-edge.deno.dev\"}\r\n    ]\r\n  }\r\n}'\r\n```\r\n\r\nKill switch: disable any one provider — disk stays locked on next reboot.\r\n\r\nSee [Split Trust Examples](docs/split-trust.md) for production deployment patterns: 2-of-2, 2-of-3 with LAN, 3 cloud providers, offsite backups, and threat model tables.\r\n\r\n### Single Server\r\n\r\n```bash\r\nclevis luks bind -d /dev/sdX tang '{\"url\":\"https://tang-edge.example.workers.dev\"}'\r\n```\r\n\r\n## API\r\n\r\n| Endpoint | Method | Description |\r\n|----------|--------|-------------|\r\n| `/adv` | GET | JWS advertisement with public keys |\r\n| `/adv/:thp` | GET | Advertisement signed by specific key |\r\n| `/rec/:thp` | POST | ECMR key recovery (clevis calls this at boot) |\r\n| `/rotate` | POST | Rotate all keys (requires `Authorization: Bearer \u003ctoken\u003e`) |\r\n| `/` | GET | Health check |\r\n\r\n## Development\r\n\r\n```bash\r\nbun run dev           # wrangler dev (CF emulator)\r\nbun run dev-server.ts # standalone (in-memory storage)\r\nbun test              # 200 tests\r\n```\r\n\r\n## Architecture\r\n\r\n```\r\nsrc/\r\n├── index.ts              # Hono app + Cloudflare Workers entry point\r\n├── crypto/\r\n│   ├── ecmr.ts           # P-521 ECMR (@noble/curves)\r\n│   ├── jwk-utils.ts      # JWK thumbprint, validation\r\n│   ├── jws.ts            # JWS signing (ES512)\r\n│   └── keygen.ts         # Key pair generation\r\n├── routes/\r\n│   ├── adv.ts            # GET /adv, GET /adv/:thp\r\n│   ├── rec.ts            # POST /rec/:thp\r\n│   └── rotate.ts         # POST /rotate\r\n├── storage/\r\n│   ├── interface.ts      # TangStorage interface\r\n│   ├── kv-store.ts       # Key management (CRUD, rotation)\r\n│   ├── types.ts          # TypeScript types\r\n│   └── adapters/         # CloudflareKV, DenoKV, DynamoDB, Firestore,\r\n│                         # NetlifyBlobs, AzureTable, VercelKV,\r\n│                         # Supabase, FastlyKV, FileSystem, Memory\r\n└── platforms/            # Entry points per provider\r\n    ├── deno.ts\r\n    ├── aws-lambda.ts\r\n    ├── gcp.ts\r\n    ├── netlify.ts\r\n    ├── azure-functions.ts\r\n    ├── vercel.ts\r\n    ├── supabase.ts\r\n    ├── fastly.ts\r\n    └── bun.ts\r\n```\r\n\r\n## How it Works\r\n\r\n1. **Setup**: `clevis luks bind` fetches Tang's public keys and encrypts a secret into the LUKS header\r\n2. **Boot**: `clevis luks unlock` sends a blinded key to `/rec/:thp`, Tang performs ECMR (EC Multiply-and-Replace), returns the result\r\n3. **Unlock**: clevis unblinds the response to recover the original secret → LUKS decrypts the disk\r\n\r\nThe server never sees the actual encryption key — it only performs a mathematical operation on blinded data. This is why Tang public keys are safe to expose and why the protocol is secure by design.\r\n\r\n## Client Setup\r\n\r\nSee [clevis documentation](https://github.com/latchset/clevis) for LUKS binding. tang-edge is a standard Tang server — any clevis client works without modifications.\r\n\r\n## Security\r\n\r\n- **Tang protocol is safe by design** — public keys are not secret, ECMR is useless without the LUKS header\r\n- **ROTATE_TOKEN** — set as secret/env var, never in config files\r\n- **WAF recommended** — IP whitelist + rate limiting on your edge platform (e.g. Cloudflare WAF)\r\n- **Kill switch** — disable the worker/function to prevent unlock on next reboot (already-running machines are unaffected; for immediate lock use `cryptsetup close` via SSH)\r\n- **Split trust** — combine multiple providers with `clevis sss`\r\n- **Timing-safe token comparison** — rotation endpoint uses constant-time equality\r\n- **Input validation** — curve, coordinates, and key type are strictly checked\r\n\r\nSee [SECURITY.md](SECURITY.md) for vulnerability reporting.\r\n\r\n## Compliance\r\n\r\nLUKS disk encryption with Network-Bound Disk Encryption (NBDE) helps satisfy data-at-rest encryption requirements across regulatory frameworks:\r\n\r\n- **GDPR** (Art. 32) — appropriate technical measures for data protection\r\n- **HIPAA** (§164.312) — encryption of electronic protected health information\r\n- **PCI-DSS** (Req. 3.4) — render stored cardholder data unreadable\r\n\r\nSplit Trust across providers adds defense-in-depth: no single cloud compromise exposes encryption keys.\r\n\r\n\u003e tang-edge is a cryptographic tool, not a certified product. Consult your compliance team for audit-specific requirements.\r\n\r\n## License\r\n\r\nGPL-3.0-only\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftang-edge%2Ftang-edge","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftang-edge%2Ftang-edge","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftang-edge%2Ftang-edge/lists"}