Security & Trust
Every statement below is a record in a claim register with an evidence status. Statements we cannot yet evidence — certifications, service-level commitments, customer references, production verification — are withheld rather than implied.
Read the labels. Implemented — not production-verified means the control exists and is tested in the development environment; no production deployment exists yet. Designed and Planned describe intent, not availability.
| Id | Statement | Evidence status | Category |
|---|---|---|---|
TC-001 | Consequential actions are authorized server-side; the browser and model output are never trusted for authorization. | Implemented — not production-verified | security |
TC-002 | Every tenant-owned record carries organization ownership and cross-tenant access is denied at the service layer. | Implemented — not production-verified | security |
TC-003 | Privileged effects fail closed when authorization, tenant, audit or evidence prerequisites are absent. | Implemented — not production-verified | security |
TC-004 | Credentials are stored encrypted, referenced by opaque identifiers, and never returned to a caller or placed in model prompts. | Implemented — not production-verified | security |
TC-005 | Audit and evidence records are append-only and separate provenance (where a requirement came from) from proof (what actually happened). | Implemented — not production-verified | governance |
TC-006 | Kill switches can halt governed execution for providers, tools, integrations, seats and projects. | Implemented — not production-verified | security |
TC-007 | Model providers are interchangeable adapters; changing a provider never changes what a seat is authorized to do. | Implemented — not production-verified | governance |
TC-008 | Every running environment reports the exact source commit it was built from. | Implemented — not production-verified | operations |
TC-009 | Backup posture is derived from recorded backup and restore-check evidence, not from configuration alone. | Implemented — not production-verified | operations |
TC-010 | Enterprise identity federation (SSO / SCIM). | Planned | identity |
TC-011 | Responsible disclosure programme. | Designed | trust |
TC-020 | Accessibility: WCAG 2.2 AA-compatible practices are targeted; no formal conformance audit has been performed. | Designed | trust |
Not claimed
We do not currently hold SOC 2, ISO/IEC 27001 or HIPAA attestations, do not offer an uptime SLA, and do not operate a production environment. Trust and procurement documents (DPA, subprocessors, privacy and retention terms) are being prepared and will be published only after legal review and Founder authorization.
Responsible disclosure
Report a suspected vulnerability through the contact route. Programme terms are designed and not yet approved.