Scan the project locally without sending source or credentials. Then inspect the offer and lint an exact signed mandate.
npx tollary fit-check --project .
npx tollary inspect --source guide-aws-kms
npx tollary lint --input ./guard-request.json --source guide-aws-kmsThe KMS role should be unable to bypass your gateway. Tollary never receives AWS credentials or KMS signing permission.
A fit-check is advisory and incomplete. Review IAM and key policies yourself; public beta is Base Sepolia only.