Skip to content
Trust & security

Security you can check.

Security and sovereignty are design constraints we hold from the first commit, and most of them run as CI gates. There is no closing phase.

The spine

Compliance. Product. Infrastructure. Operations.

Compliance

The questionnaires procurement and security teams ask for: typed, maintained, and requestable from the document library. Each is completed and carries its review date.

Certification questionnaire

CAIQ v4

Cloud Security Alliance Consensus Assessment, completed for our stack. The standard cloud-security questionnaire.

on requestRequest CAIQ v4

Certification questionnaire

SIG

Shared Assessments Standardized Information Gathering questionnaire. Third-party risk, answered in full.

on requestRequest SIG

Certification questionnaire

HECVAT Full

Higher Education Community Vendor Assessment Toolkit, for university procurement and research offices.

Product

What the software itself enforces, on every request.

Models

Zero-retention

No training on your data, no retention by model providers. Inference runs and leaves nothing behind.

zero-retention

Accessibility

WCAG 2.2 AA

Accessibility is gated in CI rather than audited at the end. Everything we ship clears AA contrast and interaction.

axe + contrast · CI

Infrastructure

Where systems run and how tenants are kept apart.

Data residency

Onshore, always

Every system runs in-country on AWS Sydney. Your data never leaves the jurisdiction.

ap-southeast-2

Tenant isolation

Row-level security

Isolation is enforced in the database, below the application, and proven by a harness on every CI run.

pgTAP harness · CI

Operations

How every change ships.

Supply chain

Signed provenance

SLSA build provenance and a signed SBOM, verified in-CI. You can check exactly what shipped.

SLSA · SBOM

App security

Scanned continuously

Static analysis and secret scanning on every change: CodeQL, Semgrep, and gitleaks gate the build.

SAST · secrets
Document library

Every artifact, listed.

Public documents open directly. Gated ones arrive by email once we know who’s asking. No artifact routes to a generic contact form.

CAIQ v4on request

CAIQ v4 questionnaire

Cloud Security Alliance Consensus Assessment, completed for our stack.

questionnaire · updated Request CAIQ v4 questionnaire
SIGon request

SIG questionnaire

Shared Assessments SIG: the standard third-party risk questionnaire.

questionnaire · updated Request SIG questionnaire
HECVAT Fullon request

HECVAT Full questionnaire

Higher Education Community Vendor Assessment, for university procurement teams.

questionnaire · updated Request HECVAT Full questionnaire
Internalon request

Isolation white paper

How row-level isolation is enforced at the database and proven by a CI harness.

whitepaper · updated Request Isolation white paper
Internalon request

Due-diligence intake

Our structured due-diligence intake. Send yours, or start from ours.

questionnaire · updated Request Due-diligence intake
Internalon request

Sovereign reference architecture

How a sovereign build is put together: local open-weight inference, a client-owned data plane, and air-gap options.

whitepaper · updated Request Sovereign reference architecture
Internalpublic

Subprocessor register

Every third party that touches client data, with purpose and region.

register · updated View Subprocessor register
Internalpublic

RLS isolation harness result

The tenant-isolation harness result, written to the database on every CI run.

live-check · updated View RLS isolation harness result
RFC 9116public

security.txt

Responsible-disclosure contact and policy, machine-readable at the standard path.

disclosure · updated View security.txt

Request a gated artifact

Tell us who you are and which document you need. We’ll send it over. NDAs welcome.

One reply from an engineer, typically within two business days.

Verification

The gates run on every build.

Most trust pages list aspirations. Ours points at checks that pass or fail on every commit: quality, isolation, supply-chain, and security gates, plus a tenant-isolation harness that writes its verdict to the database. No badge images. The tooling behind the gates is going public as licence reviews clear; install what is published and run it on your own code.

What we don’t claim yet

SOC 2 and ISO 27001 are on our roadmap, not our wall. Until an auditor signs, what you get are the controls themselves: RLS-forced tables, zero-retention model calls, and a validation gate on every commit, plus the completed questionnaires above.

  • Quality gatetsc · RLS · a11y
  • ProvenanceSLSA · SBOM
  • CodeQLSAST
  • SemgrepSAST
  • gitleakssecret scan
  • Lighthouseperf budgets
Isolation harnesscheckinglatest run loading…

The same checks run as a fixed-scope review. The RLS review ›

Subprocessors

Who touches the data.

The complete list: purpose and region stated plainly, including the ones that aren’t onshore.

SubprocessorPurposeRegion
SupabaseDatabase, auth & storageap-southeast-2 (Sydney)
AWSInfrastructure underlying Supabaseap-southeast-2 (Sydney)
VercelHosting & CDNGlobal edge · US compute
AnthropicAI inference (zero data retention)US
StripeBillingUS · global
ResendTransactional emailUS
SentryError monitoringUS
DeepgramVoice transcriptionUS
Updates

What changed, and when.

  1. Sovereign reference architecture

    Sovereign reference architecture added to the document library (request access), backing the sovereign offering published at /what-we-build.

  2. Trust centre launched

    Document library, subprocessor register, dated updates feed, and the responsible-disclosure route published at /trust and /.well-known/security.txt.

  3. Isolation badge made public

    The RLS isolation harness result became publicly readable through a definer RPC (trust_badge_public). Live proof without a staff session.

  4. Public intake hardened

    Marketing contact submissions moved to a SECURITY DEFINER intake RPC with per-IP rate limiting; the leads table has no anonymous write policy.

Responsible disclosure

Spotted something? Tell us.

Found a vulnerability in anything we run? Email us directly. No forms, no triage bots. We acknowledge reports within three business days, keep you informed through to resolution, and credit good-faith research if you want the credit.

Acknowledged within
three business days

Bring us the work. We’ll bring the governance.

Two hours, your team, the real work. Everything on this page ships with it.