Where it runs, who can do what,
and what is recorded.
Answerable before an engagement rather than during it.
Last reviewed 24 September 2026. Reviewed quarterly, and whenever the answer changes.
Inside your boundary.
Built to run inside your boundary: self-hosted or your private cloud, air-gap on request. The design is portable.
In a self-hosted or private-cloud deployment, policyholder data does not leave your environment, except to the model provider you configure. Nothing you run trains us, or anyone.
Your identity provider, from day one.
Your identity provider and your authorization configuration plug in from day one, and least privilege is the default.
Agents are principals, not plumbing: an agent acts on behalf of a named requester, with a grant id, and it cannot approve, merge, or reach a table any other way.
Every action enters through one door. There is no side path to a table or a vendor, so there is exactly one place to authenticate, authorize, scope the tenant, and record.
Written in the same commit, append-only.
The record is written in the same commit as the work, and it is append-only, enforced below the application: the database refuses UPDATE and DELETE, and the role that serves the application cannot lift them. The chain that would make the sequence self-checking is not built, and we are not going to call this tamper-evident.
Every row carries the same keys, so any two pieces of evidence join on one column, across services.
Denials are recorded with the rule that matched: no merge, no approval requested, and a row that names the rule.
The port is the contract.
The model port is the contract. Anthropic ships today; other providers and local models drop in behind the same port. Fine-tuning pipelines are out of scope.
Every receipt names the model and the prompt version that ran, so the record stays whole across a model change.
Retention, and what logs carry.
Retention is declared per engagement and written into the agreement. Retention policies are set per client build and per class of information, rather than one window for everything.
Logs redact protected health information while preserving a token, so an agent can still triage a record without the log carrying the data.
Both of the above are confirmed by the engineer who built them and are listed on the capability-status page with that basis stated. Ask for them in writing and you will get them in writing.
What the website itself does.
Cloudflare Web Analytics, cookieless. Google Fonts. The form stores exactly the fields the privacy page names. Nothing is deleted on a schedule.
What we do not hold.
We hold no certification, accreditation, or regulatory approval, and we do not assert one.
We answer the vendor security questionnaire in writing before an engagement begins, with the capabilities that are not built yet named in the answers.
What is not built is listed with its status, dated: capability status.
Start with the workflow you
already have to build.
Thirty minutes, with the engineers who build the line. You name the workflow and the examiner you answer to; we tell you what a governed build of it looks like, what it costs, and when it can start. Bring your compliance lead.
Inquiries are answered within one business day, by someone who can answer them.
