AES-256-GCM at rest, HKDF per-machine subkey, every read in the audit entangled state. Replaces .env for tenant secrets — your machine's keys, scoped per app and environment.
Phase 2.1
Tenant-scoped vault. Paste a zsm_ key minted in your machine's admin panel — every call below is signed with it and scoped to one state_machine_id.
0 keys · last loaded — Zeqonds
Paste a zsm_ key and click Reload to fetch.
Subscriptions appear here after you create them.
These act as you, not as a key — ownership is about identity, so the
zsm_ field above is not used here.