Security at PipKey
Licensing is trust infrastructure.
PipKey is being designed with the assumption that licensing decisions can protect customer revenue, product access and sensitive commercial relationships. Security therefore has to be part of the architecture rather than a feature added later.
Secure by design
We minimise exposed surface area, keep the public website separate from licensing infrastructure, use scoped access controls and avoid putting sensitive implementation details into public interfaces.
Cryptographic verification
PipKey's licensing core uses modern cryptographic techniques for licence assertions and verification. Private signing material is treated as secret infrastructure and must never be embedded in public applications, repositories or the marketing website.
Privacy minimisation
Activation and installation data should be limited to what is needed to evaluate entitlement, detect relevant risk, support customers and operate the service. PipKey is being developed with UK GDPR obligations and data-retention decisions considered from the outset.
Auditable decisions
Important licence and administrative actions are designed to create an operational history so that significant changes can be investigated and reconciled. Auditability is particularly important for enterprise, reseller and delegated licensing models.
Resilience and recovery
A licensing platform cannot be treated as production-ready simply because it starts successfully. PipKey's release gates include backup and recovery procedures, deployment safeguards, monitoring, testing and resilience exercises.
Responsible disclosure
If you believe you have discovered a security issue affecting PipKey, please contact PluginPip privately at security@pipkey.co.uk. Please do not publish sensitive details before we have had a reasonable opportunity to investigate and respond.
Current status
PipKey Server 1.0 is live in production. The wider PipKey 1.1 commercial platform is being developed behind separate release gates, with customer-facing administration, commerce automation, usage metering and developer tooling introduced only after their security, migration and recovery checks are complete. Planned capabilities should not be read as generally available until explicitly marked as released.