Security at PipKey

Licensing is trust infrastructure.

PipKey is being designed with the assumption that licensing decisions can protect customer revenue, product access and sensitive commercial relationships. Security therefore has to be part of the architecture rather than a feature added later.

Secure by design

We minimise exposed surface area, keep the public website separate from licensing infrastructure, use scoped access controls and avoid putting sensitive implementation details into public interfaces.

Cryptographic verification

PipKey's licensing core uses modern cryptographic techniques for licence assertions and verification. Private signing material is treated as secret infrastructure and must never be embedded in public applications, repositories or the marketing website.

Privacy minimisation

Activation and installation data should be limited to what is needed to evaluate entitlement, detect relevant risk, support customers and operate the service. PipKey is being developed with UK GDPR obligations and data-retention decisions considered from the outset.

Auditable decisions

Important licence and administrative actions are designed to create an operational history so that significant changes can be investigated and reconciled. Auditability is particularly important for enterprise, reseller and delegated licensing models.

Resilience and recovery

A licensing platform cannot be treated as production-ready simply because it starts successfully. PipKey's release gates include backup and recovery procedures, deployment safeguards, monitoring, testing and resilience exercises.

Responsible disclosure

If you believe you have discovered a security issue affecting PipKey, please contact PluginPip privately at security@pipkey.co.uk. Please do not publish sensitive details before we have had a reasonable opportunity to investigate and respond.

Current status

PipKey Server 1.0 is live in production. The wider PipKey 1.1 commercial platform is being developed behind separate release gates, with customer-facing administration, commerce automation, usage metering and developer tooling introduced only after their security, migration and recovery checks are complete. Planned capabilities should not be read as generally available until explicitly marked as released.