If the customer holds the signing key, the chain of custody is meaningless. Whose key signs the log?
Ours, in an HSM behind attested hardware (AWS Nitro Enclaves or GCP Confidential VM), under our SOC 2 attestation. The agent runtime never sees the key. The customer can re-verify offline against the public anchor, but they cannot rewrite history. That separation is the entire point.