Security review
Every answer a review committee asks for in the first ten minutes, stated plainly and completely: where it runs, what leaves, who holds the keys, what code is inside, and what happens when the licence ends.
On your machines, in your estate, including entirely disconnected environments. The kernel binds the loopback interface and refuses any client that is not local.
In the default mode, nothing. There is no outbound call of any kind. Where independent witnessed time is required, a single cryptographic digest is sent to a public timestamp authority under RFC 3161. Never the file, never its contents, never a name.
You do. The signing key is generated on your own machine on first run, and it is never transmitted and never escrowed with us.
No. It is filed as architecture. No egress, no account, no dependency on any network. The guarantee is structural rather than configured.
Yes. It ships readable by design, so your security function can satisfy itself line by line. Reading is granted under licence; redistribution and derivative works are not.
A small set of permissively licensed libraries implementing published mathematics: Ed25519 to RFC 8032, SHA-256, RFC 3161 timestamping. Licence texts ship with the software. Using audited public implementations is deliberate: an opposing expert checks the mathematics against a public reference, which is a stronger position than a private one.
Describe the system, what it decides, and what it would cost you to be unable to prove it. A written scope follows before any call.
Ways to begin: