Platform security

Release and asset verification

CertaNox combines multiple trust boundaries instead of betting everything on one local lock: controlled delivery, signed releases, device identity, server-authoritative policy, asset-aware protection, verification and controlled recovery.

CNX
SOFTWARE TRUSTASSET TRUSTPOLICY TRUST

Layered security

Not one check. A chain of trust.

Each layer has a different job. Together they reduce reliance on a single device, file marker, local clock or application state.

01

Controlled software delivery

Official access begins through CertaNox Secure Delivery and the approved LaunchGuard release path.

02

Signed release trust

Release integrity and publisher identity are checked so altered or unexpected software is not treated as official CertaNox.

03

Device-bound access

Every public licence is limited to one active device, with controlled reset and recovery boundaries.

04

Server-authoritative policy

Licence time and capabilities come from CertaNox policy and server UTC rather than trusting the Windows clock or an editable local label.

05

Asset-aware protection

Images, media, documents, archives and executables use protection strategies appropriate to their format and integrity requirements.

06

Verifiable evidence

Protected assets can carry or reference integrity, provenance, transformation and investigation evidence that can be reviewed later.

07

Modern cryptography

The platform uses strong symmetric cryptography and hybrid post-quantum mechanisms in supported trust paths, without presenting cryptography as the only control.

08

Controlled recovery

Recovery-sensitive actions remain explicit, auditable operations rather than silent bypasses around normal authorization.

Three trust planes

Software. Identity. Asset.

CertaNox connects the trust of the program you run, the account/device that is authorized, and the digital asset being protected.

SOFTWARE

Is this the approved CertaNox release?

Controlled delivery, release signatures and LaunchGuard establish the software path.

IDENTITY

Is this account and device allowed?

Account-bound licensing and one-device activation establish authorization.

ASSET

What can this file prove?

Protection, manifests, proofs, capsules and verification establish asset evidence.

Public security posture

Strong claims need honest boundaries.

CertaNox strengthens authorization, provenance and evidence around protected assets, but no desktop security product can guarantee that a fully compromised operating system or captured screen can never expose content. The goal is layered control and verifiable evidence—not an impossible promise.

SignedOfficial release path
BoundOne active device
VerifiedAsset evidence

Security, reimagined around the asset.

See how the platform applies that trust model across different file families.