Skip to content
Trust & security

Security you can check.

Security and sovereignty are design constraints we hold from the first commit, and most of them run as CI gates. There is no closing phase.

The spine

Compliance. Product. Infrastructure. Operations.

Compliance

The questionnaires procurement and security teams ask for. Send us yours and we answer it; each card says whether we already hold that one, and the date it was last reviewed.

Security questionnaire

CAIQ v4

Cloud Security Alliance Consensus Assessment: the standard cloud-security questionnaire.

on requestRequest CAIQ v4 ›

Security questionnaire

SIG

Shared Assessments Standardized Information Gathering: the standard third-party risk set.

on requestRequest SIG ›

Security questionnaire

HECVAT Full

Higher Education Community Vendor Assessment Toolkit, for university procurement and research offices.

Product

What the software itself enforces, on every request.

Models

Zero-retention

No training on your data, no retention by model providers. Inference runs and leaves nothing behind.

zero-retention

Accessibility

WCAG 2.2 AA

Accessibility is gated in CI rather than audited at the end. Everything we ship clears AA contrast and interaction.

axe + contrast · CI

Infrastructure

Where systems run and how tenants are kept apart.

Data residency

Onshore data plane

Your data plane runs in-country: Postgres, auth and file storage in AWS Sydney. Two things sit outside it and we name them rather than round them off. This website is served from Vercel US compute, and model calls go to a US provider under zero-retention terms. A sovereign build removes both.

ap-southeast-2 · exceptions named

Tenant isolation

Row-level security

Isolation is enforced in the database, below the application, and proven by a harness on every CI run.

pgTAP harness · CI

Operations

How every change ships.

Supply chain

Signed provenance

SLSA build provenance and a signed SBOM, verified in-CI. You can check exactly what shipped.

SLSA · SBOM

App security

Scanned continuously

Static analysis and secret scanning on every change: CodeQL, Semgrep, and gitleaks gate the build.

SAST · secrets
Document library

Every artifact, listed.

Public documents open directly. Gated ones arrive by email once we know who’s asking. No artifact routes to a generic contact form.

CAIQ v4on request

CAIQ v4 questionnaire

Cloud Security Alliance Consensus Assessment, the standard cloud-security set.

questionnaire · updated Request CAIQ v4 questionnaire ›
SIGon request

SIG questionnaire

Shared Assessments SIG: the standard third-party risk questionnaire.

questionnaire · updated Request SIG questionnaire ›
HECVAT Fullon request

HECVAT Full questionnaire

Higher Education Community Vendor Assessment, for university procurement teams.

questionnaire · updated Request HECVAT Full questionnaire ›
Internalon request

Isolation white paper

How row-level isolation is enforced at the database and proven by a CI harness.

whitepaper · updated Request Isolation white paper ›
Internalon request

Due-diligence intake

Our structured due-diligence intake. Send yours, or start from ours.

questionnaire · updated Request Due-diligence intake ›
Internalon request

Sovereign reference architecture

How a sovereign build is put together: local open-weight inference, a client-owned data plane, and air-gap options.

whitepaper · updated Request Sovereign reference architecture ›
Internalpublic

Subprocessor register

Every third party in our own platform, with purpose, region and scope.

register · updated View Subprocessor register ›
Internalpublic

RLS isolation harness result

The tenant-isolation harness result, written to the database on every run on main.

live-check · updated View RLS isolation harness result ›
RFC 9116public

security.txt

Responsible-disclosure contact and policy, machine-readable at the standard path.

disclosure · updated View security.txt ›

Request a gated artifact

Tell us who you are and which document you need. We’ll send it over. NDAs welcome.

One reply from an engineer, typically within two business days.

Verification

The gates run in CI.

Most trust pages list aspirations. Ours points at checks that pass or fail in CI: quality, isolation, supply-chain, and security gates, plus a tenant-isolation harness that writes its verdict to the database. No badge images. All of it runs on our own platform, so read it as the standard we hold rather than as a record of client deliveries. The isolation verdict on our status page is the one claim here you do not have to take on trust: our CI writes it, and that page reads it back.

What we don’t claim yet

SOC 2 and ISO 27001 are on our roadmap, not our wall. Until an auditor signs, what you get are the controls themselves: RLS-forced tables, zero-retention model calls, and a validation gate on every commit. We hold no completed security questionnaire yet either — send us the one your procurement team uses and we answer it. The second limit is delivery history. We have not yet delivered a client system into production, so everything on this page evidences the standard we build to, not a record of systems already running in someone else’s production.

  • Quality gatetsc · RLS · a11y
  • ProvenanceSLSA · SBOM
  • CodeQLSAST
  • SemgrepSAST
  • gitleakssecret scan
  • Lighthouseperf budgets
Isolation harnesscheckinglatest run loading…

The same checks run as a fixed-scope review. The RLS review ›

Subprocessors

Who touches the data.

This website and the Cogvera Hub. Our own platform, which is also where client data sits during an engagement. Database, authentication and file storage run in ap-southeast-2. The site you are reading is served by Vercel, whose compute sits in the United States, and our AI features call a US model provider under zero-retention terms. The register below names every third party involved and marks the ones that are not onshore.

SubprocessorPurposeRegion
SupabaseDatabase, auth & storageap-southeast-2 (Sydney)
AWSInfrastructure underlying Supabaseap-southeast-2 (Sydney)
VercelHosting & CDNGlobal edge · US computeoffshore
AnthropicAI inference (zero data retention)USoffshore
StripeBillingUS · globaloffshore
ResendTransactional emailUSoffshore
SentryError monitoringUSoffshore
DeepgramVoice transcriptionUSoffshore

Systems we build for clients. Set per engagement and written into the agreement before the first commit. The default is a data plane in ap-southeast-2 with model calls under zero-retention terms. A sovereign build drops the model provider entirely and runs on hardware you own.

Updates

What changed, and when.

  1. Sovereign reference architecture

    Sovereign reference architecture added to the document library (request access), backing the sovereign offering published at /what-we-build.

  2. Trust centre launched

    Document library, subprocessor register, dated updates feed, and the responsible-disclosure route published at /trust and /.well-known/security.txt.

  3. Isolation badge made public

    The RLS isolation harness result became publicly readable through a definer RPC (trust_badge_public). Live proof without a staff session.

  4. Public intake hardened

    Marketing contact submissions moved to a SECURITY DEFINER intake RPC with per-IP rate limiting; the leads table has no anonymous write policy.

Responsible disclosure

Spotted something? Tell us.

Found a vulnerability in anything we run? Email us directly. No forms, no triage bots. We acknowledge reports within three business days, keep you informed through to resolution, and credit good-faith research if you want the credit.

Acknowledged within
three business days

Bring us the work. We’ll bring the governance.

Two hours, your team, the real work. Everything on this page ships with it.