Sindook Steward - Threat-aware key rotation for encrypted files

by
An open-source local workbench for turning recipient changes into reviewable fast or deep key-rotation plans. GPT-5.6 Sol interprets ambiguous threat signals, while deterministic policy controls recipients, approval, and execution. Keys, plaintext, ciphertext, and commands stay outside the model. Run the bundled post-quantum sample vault with Docker, approve with ROTATE, and inspect evidence of what changed and what old copies still retain.

Add a comment

Replies

Best
Maker
📌
Hi Product Hunt, I built Sindook Steward after noticing that removing someone from an encrypted file is often described as if it were a single operation. It isn't. A recipient-header update and full payload re-encryption solve different threats, and neither can erase a copy someone already kept. Steward turns that decision into a local, reviewable workflow. GPT-5.6 Sol interprets a short access request, but it never sees key material or plaintext and cannot execute anything. Deterministic policy chooses the operation, a literal ROTATE approval gates execution, and the proof ledger records both the result and the residual risk. This is an open-source, sample-vault prototype, not production key management. I would especially value feedback from security engineers and maintainers: which policy or evidence integration would make this useful in a real workflow?