Trust is stronger when the product states both what it controls and what it does not yet claim.
This Trust Center separates implemented technical controls, configuration dependencies, published evidence, commitments not yet formalized and certifications not currently held. It is designed to support serious diligence without turning architecture into marketing theatre.
17
implemented controls
4
configuration-dependent
1
items not yet published
2
certifications not claimed
Identity & Access
Roles, tenant scope, SSO policy, verified domains, JIT and SCIM-ready lifecycle.
Audit & Evidence
Append-only evidence, payload reconstruction, chained integrity, retention and legal hold.
API & Integrations
Hashed credentials, scopes, entitlements, rate limits, idempotency, signing and anti-SSRF.
Production Operations
Observability, readiness gates, production pilot controls, rollout governance and rollback discipline.
Procurement readiness
Enterprise diligence needs a route map, not a stack of PDFs.
The checklist below organizes the areas typically reviewed by technical, Security, Privacy, Legal and Procurement teams.
EID-1.0Enterprise identity
Review SSO provider, verified domain, JIT, group mapping, fallback and SCIM lifecycle.
TENANCYTenant & authorization
Confirm organization/workspace/department, roles and backend validation for sensitive flows.
DOCS-2.0Data and privacy
Map prompts, responses, analytics, integrations, providers, retention and applicable legal bases.
AUD-2.0Audit
Validate append-only evidence, integrity checks, retention, legal hold and HMAC when required.
INT-1.0Integrations
Review OAuth, tenant safety, datasets, minimization, writeback and authorization ownership.
API-1.0API
Define scopes, credentials, rate limits, idempotency, webhook signing and allowed destinations.
GLR-1.0Continuity
Review rollback, health, readiness, responsibilities and contractual commitments not yet published.
BILL-1.0 / LEGALCommercial and legal
Align plan, pricing, DPA, Privacy, Terms, SLA and customer-specific requirements.
Evidence catalog
What can be inspected today
Published technical documents and still-pending items appear in the same catalog so the absence of evidence is not confused with an implemented control.
Security architecture
PublishedDOCS-2.0Defense-in-depth model, tenant scope, RLS, service role, secrets and API controls.
Audit and integrity
PublishedAUD-2.0Append-only evidence, hashes, chain verification, retention and legal hold.
Identity & SSO
PublishedEID-1.0SSO, verified domains, JIT, group mapping, SCIM and external dependencies.
API & Webhooks
PublishedAPI-1.0Credentials, scopes, rate limiting, idempotency and fail-closed webhook signing.
Integration Hub
PublishedINT-1.0Catalog, OAuth, tenant safety, minimization, health, sync and readiness.
Continuity and recovery
PublishedDOCS-2.0Recovery principles, evidence preservation and current absence of public RPO/RTO commitments.
Technical privacy
PublishedDOCS-2.0Minimization, scope and provider flows, separate from the final legal Privacy Policy.
Suppliers and subprocessors
PublishedDOCS-2.0Technical supplier governance and the boundary between provider catalog and legal subprocessor register.
Legal Privacy Policy
Published for approvalLEGAL-2.0Full policy published; formal legal approval remains a human governance step.
Data Processing Addendum
Contracting-readyLEGAL-2.0Controller-processor baseline with security, incidents, subprocessors and transfers.
Formal subprocessor register
PublishedLEGAL-2.0Public inventory with core and conditional providers.
SLA / RPO / RTO
Decision publishedLEGAL-2.0Operational baseline and boundary between public SLO and contracted Enterprise SLA.
SOC 2 Type II
Not certifiedCERTNo SOC 2 Type II certification is claimed.
ISO/IEC 27001
Not certifiedCERTNo ISO/IEC 27001 certification is claimed.
Control matrix
Current technical posture
Filter by state. Version values point to internal product contracts where applicable.
TENANCYOrganization is the primary boundary; workspace and department refine operational scope. Sensitive functions revalidate context.
EID-1.0Enterprise roles are applied in routes and backend; sensitive operations remain constrained according to contract.
EID-1.0The control plane exists, but mandatory SSO depends on an active provider and verified domain.
EID-1.0Provisioning can map external groups to configured role, workspace and department.
EID-1.0Endpoints exist but require runtime bearer token and organization configuration.
AUD-2.0ComplianceAuditEvent is service-role written and does not expose generic update/delete to users.
AUD-2.0Integrity verification reconstructs the payload and recalculates payload_hash before checking the chain.
AUD-2.0Baseline is SHA-256; HMAC-SHA256 requires COMPLIANCE_HMAC_SECRET.
AUD-2.0Events receive retention_until with a current technical baseline of approximately seven years.
AUD-2.0Legal-hold operations preserve evidence and produce additional audit evidence.
API-1.0Raw keys are returned once; persistence stores prefix and SHA-256 hash.
API-1.0 / ENT-1.0Scope cannot bypass api_access entitlement or tenant boundaries.
API-1.0Persistent one-minute buckets are enforced per credential.
API-1.0Run creation requires Idempotency-Key and rejects reuse with a different request.
API-1.0HMAC delivery requires WEBHOOK_SIGNING_SECRET and fails closed when unavailable.
API-1.0HTTPS, private-host rejection, DNS validation and redirects disabled.
ENT-1.0Features and limits are enforced in backend flows with usage snapshots and auditable decisions.
BILL-1.0The SaaS usage ledger can be reconciled against canonical measurement usage.
OBS-1.0Operational health can report insufficient evidence instead of manufacturing a green state.
GLR-1.0Readiness blocks launch when critical failures exist and uses a policy-defined target score.
PLC-1.0Pilot evidence and rollout states control expansion toward production.
LEGAL-2.0Full public policy available at /en/privacy; formal legal approval remains an organizational act before PRCL approval.
LEGAL-2.0B2B DPA available at /en/legal/dpa and binding when incorporated into the applicable commercial instrument.
LEGAL-2.0Public inventory available at /en/legal/subprocessors with core and conditional providers.
LEGAL-2.0Baseline service levels and continuity objectives are available at /en/legal/service-levels.
—No SOC 2 Type II certification is claimed.
—No ISO/IEC 27001 certification is claimed.
—No public independent pentest report or attestation is currently published.