Skip to content
Trust Center

Trust is stronger when the product states both what it controls and what it does not yet claim.

This Trust Center separates implemented technical controls, configuration dependencies, published evidence, commitments not yet formalized and certifications not currently held. It is designed to support serious diligence without turning architecture into marketing theatre.

17

implemented controls

4

configuration-dependent

1

items not yet published

2

certifications not claimed

The matrix describes the current technical control posture. It is not a legal opinion, certification report, penetration-test attestation or contractual SLA.

Identity & Access

Roles, tenant scope, SSO policy, verified domains, JIT and SCIM-ready lifecycle.

Audit & Evidence

Append-only evidence, payload reconstruction, chained integrity, retention and legal hold.

API & Integrations

Hashed credentials, scopes, entitlements, rate limits, idempotency, signing and anti-SSRF.

Production Operations

Observability, readiness gates, production pilot controls, rollout governance and rollback discipline.

Procurement readiness

Enterprise diligence needs a route map, not a stack of PDFs.

The checklist below organizes the areas typically reviewed by technical, Security, Privacy, Legal and Procurement teams.

01EID-1.0

Enterprise identity

Review SSO provider, verified domain, JIT, group mapping, fallback and SCIM lifecycle.

02TENANCY

Tenant & authorization

Confirm organization/workspace/department, roles and backend validation for sensitive flows.

03DOCS-2.0

Data and privacy

Map prompts, responses, analytics, integrations, providers, retention and applicable legal bases.

04AUD-2.0

Audit

Validate append-only evidence, integrity checks, retention, legal hold and HMAC when required.

05INT-1.0

Integrations

Review OAuth, tenant safety, datasets, minimization, writeback and authorization ownership.

06API-1.0

API

Define scopes, credentials, rate limits, idempotency, webhook signing and allowed destinations.

07GLR-1.0

Continuity

Review rollback, health, readiness, responsibilities and contractual commitments not yet published.

08BILL-1.0 / LEGAL

Commercial and legal

Align plan, pricing, DPA, Privacy, Terms, SLA and customer-specific requirements.

Evidence catalog

What can be inspected today

Published technical documents and still-pending items appear in the same catalog so the absence of evidence is not confused with an implemented control.

Open Documentation Center

Security architecture

Published
DOCS-2.0

Defense-in-depth model, tenant scope, RLS, service role, secrets and API controls.

Audit and integrity

Published
AUD-2.0

Append-only evidence, hashes, chain verification, retention and legal hold.

Identity & SSO

Published
EID-1.0

SSO, verified domains, JIT, group mapping, SCIM and external dependencies.

API & Webhooks

Published
API-1.0

Credentials, scopes, rate limiting, idempotency and fail-closed webhook signing.

Integration Hub

Published
INT-1.0

Catalog, OAuth, tenant safety, minimization, health, sync and readiness.

Continuity and recovery

Published
DOCS-2.0

Recovery principles, evidence preservation and current absence of public RPO/RTO commitments.

Technical privacy

Published
DOCS-2.0

Minimization, scope and provider flows, separate from the final legal Privacy Policy.

Suppliers and subprocessors

Published
DOCS-2.0

Technical supplier governance and the boundary between provider catalog and legal subprocessor register.

Legal Privacy Policy

Published for approval
LEGAL-2.0

Full policy published; formal legal approval remains a human governance step.

Data Processing Addendum

Contracting-ready
LEGAL-2.0

Controller-processor baseline with security, incidents, subprocessors and transfers.

Formal subprocessor register

Published
LEGAL-2.0

Public inventory with core and conditional providers.

SLA / RPO / RTO

Decision published
LEGAL-2.0

Operational baseline and boundary between public SLO and contracted Enterprise SLA.

SOC 2 Type II

Not certified
CERT

No SOC 2 Type II certification is claimed.

ISO/IEC 27001

Not certified
CERT

No ISO/IEC 27001 certification is claimed.

Control matrix

Current technical posture

Filter by state. Version values point to internal product contracts where applicable.

Tenant scope
Implemented
TENANCY

Organization is the primary boundary; workspace and department refine operational scope. Sensitive functions revalidate context.

Role-based access control
Implemented
EID-1.0

Enterprise roles are applied in routes and backend; sensitive operations remain constrained according to contract.

SSO and verified domains
Configuration-dependent
EID-1.0

The control plane exists, but mandatory SSO depends on an active provider and verified domain.

JIT provisioning and group mapping
Implemented
EID-1.0

Provisioning can map external groups to configured role, workspace and department.

SCIM lifecycle
Configuration-dependent
EID-1.0

Endpoints exist but require runtime bearer token and organization configuration.

Append-only evidence
Implemented
AUD-2.0

ComplianceAuditEvent is service-role written and does not expose generic update/delete to users.

Payload reconstruction
Implemented
AUD-2.0

Integrity verification reconstructs the payload and recalculates payload_hash before checking the chain.

HMAC chain
Configuration-dependent
AUD-2.0

Baseline is SHA-256; HMAC-SHA256 requires COMPLIANCE_HMAC_SECRET.

Evidence retention
Implemented
AUD-2.0

Events receive retention_until with a current technical baseline of approximately seven years.

Legal hold
Implemented
AUD-2.0

Legal-hold operations preserve evidence and produce additional audit evidence.

Hashed API credentials
Implemented
API-1.0

Raw keys are returned once; persistence stores prefix and SHA-256 hash.

API scopes + entitlements
Implemented
API-1.0 / ENT-1.0

Scope cannot bypass api_access entitlement or tenant boundaries.

Persistent rate limiting
Implemented
API-1.0

Persistent one-minute buckets are enforced per credential.

Write idempotency
Implemented
API-1.0

Run creation requires Idempotency-Key and rejects reuse with a different request.

Webhook signing
Configuration-dependent
API-1.0

HMAC delivery requires WEBHOOK_SIGNING_SECRET and fails closed when unavailable.

Anti-SSRF protection
Implemented
API-1.0

HTTPS, private-host rejection, DNS validation and redirects disabled.

Entitlements and usage
Implemented
ENT-1.0

Features and limits are enforced in backend flows with usage snapshots and auditable decisions.

Billing reconciliation
Implemented
BILL-1.0

The SaaS usage ledger can be reconciled against canonical measurement usage.

Observability
Implemented
OBS-1.0

Operational health can report insufficient evidence instead of manufacturing a green state.

Go-live gate
Implemented
GLR-1.0

Readiness blocks launch when critical failures exist and uses a policy-defined target score.

Production Pilot and Launch Control
Implemented
PLC-1.0

Pilot evidence and rollout states control expansion toward production.

Public Privacy Policy
Not published
LEGAL-2.0

Full public policy available at /en/privacy; formal legal approval remains an organizational act before PRCL approval.

DPA
Not published
LEGAL-2.0

B2B DPA available at /en/legal/dpa and binding when incorporated into the applicable commercial instrument.

Public subprocessor register
Not published
LEGAL-2.0

Public inventory available at /en/legal/subprocessors with core and conditional providers.

Public SLA, RPO and RTO
Not published
LEGAL-2.0

Baseline service levels and continuity objectives are available at /en/legal/service-levels.

SOC 2 Type II
Not certified
—

No SOC 2 Type II certification is claimed.

ISO/IEC 27001
Not certified
—

No ISO/IEC 27001 certification is claimed.

Independent penetration test
Not published
—

No public independent pentest report or attestation is currently published.