• Ensure no keys live on developers machines.
  • Ensure all commits to our repositories are signed by our corporate identity provider.
  • Have fine-grained verification for commits made by our CI automation.