Certificate Lifecycle Service  ·  View 09 of 21  ·  Data

Data Flow

From a declared policy to a published revocation list, and the single write that means something different from all the others.

Editable source SVG draw.io All views
Declared Policy repository git, reviewed Domain register per tenant Owner directory team per identity Requested Order record subject · profile Validation evidence how control was proved Issued Issuance ledger append-only, 10 y Certificate record issuer + serial CT entry public certs only Distributed Delivery receipt where it was written Bundle version report per relying party Observed Probe observation serial seen serving Discovery finding scan · CT watch Divergence registry vs reality Reported Expiry projection shortest life first Revocation list CRL · OCSP Evidence export audit · SIEM sets lifecycle state Certificate Lifecycle Service — Data Flow Data store External / third party Risk / gap Security / platform Interface / broker synchronous The only write that moves a certificate into SERVING comes from the observation stage. Every other stage records intent; this one records fact. v 1.0 · owner Data Architecture · date 2026-09

The asymmetry

  • Five of the six stages record intent: what was declared, requested, issued, distributed, reported.
  • One stage records fact. The observation stage is the only writer that can move a certificate into SERVING, and the only input the expiry clock is raised from.

Evidence

  • The issuance ledger is append-only and retained 10 years — at least the life of the longest-lived root plus three years, because a root issued today outlives the engineers who issued it.
  • Validation evidence is retained 3 years: it is the proof the platform was entitled to issue for someone else's domain.

Assumptions

  • ~70,000 live certificate records, ~17 million issuance records per year, ~1.1 million probe observations per day.
  • Probe observations at full fidelity for 90 days, then daily aggregate for 2 years.