Overview
Compliance
Section titled “Compliance”Compliance-evidence readback + signed exports (list, get, export). Reads are a classification lens over AuditEventBinding; only classifier-marked exportable kinds appear on the wire. Signed export is caller-plugged via SigningKeyBinding — deployments without a signing key get 404 signing-not-configured. Bundle envelope matches provenance.export + audit-bundle byte-for-byte so verifiers reuse one verifyEd25519 wrapper across all three surfaces. Redaction happens when evidence is generated, not at the export boundary — records are stored already redacted.