Trust and data
What is actually in place
Enterprise software deals stall in security review, so this page exists to answer the questions early rather than by email later. Everything below is in place today and can be evidenced. Anything we cannot evidence is not on this page.
- Sheet
- A-03
- Title
- Specification
- Issued for
- Security review
- Drawn by
- Snilld
Where it lives, and who can reach it
Residency, the tenancy boundary, and how permission is decided.
Where your data lives
In placeProduction systems run in the India region — Oracle Cloud, Hyderabad — on infrastructure we operate. Data residency is a configuration we can state precisely rather than a claim we imply, and we will put it in a contract.
One tenant can never read another
In placeIsolation is enforced at the database with Postgres row-level security, not by application code alone. That distinction matters: an application bug cannot widen the boundary, because the boundary is not in the application.
Access is role-based, down to the record
In placeRoles run from platform owner through site administrator to end user, and permissions are checked on the server on every request rather than hidden in the interface. Sign-in is passwordless — a provider account or a one-time link — so there are no shared passwords to rotate or leak.
What we do with it, and who else sees it
What your material is used for, and every third party in the path.
We do not train on your data
In placeYour documents and records are processed to produce your output and for no other purpose. Nothing you give us is used to train a model, ours or anyone else’s, and nothing is pooled across clients. This goes in the contract, not just on this page.
Who else touches it
In placeWe name every sub-processor rather than describing them as "trusted partners". Today that means a model provider for reading and reasoning, a managed Postgres host, object storage, and a transactional mail provider. The current list, with what each one sees, is available on request and forms part of any data processing agreement.
Proving what happened
The record of who changed what, and the controls that keep a wrong answer from passing silently.
Corrections add. They never overwrite.
In placeRecords that matter are written to an append-only trail. A correction is a new entry that supersedes the old one, so the question "what did this say in March, and who changed it" has an answer. Audit trails that allow edits are not audit trails.
Nothing silent reaches a customer
In placeThe confidence gate is a security control as much as a quality one. Anything the system is unsure about is marked and queued for a person rather than filled with a plausible value. The failure mode we design against is a confident wrong answer, because that is the one nobody catches.
Change safety
In placeThe platform that runs in production carries roughly 1,290 automated tests, run on every push. That number is not a security certificate, but it is the honest measure of whether a change can quietly break something that was working.
Your rights, and your exit
Statutory requests, and leaving with everything you gave us.
Built for Indian data protection law
In placeConsent is versioned, so we can show what a person agreed to and when. Personal identifiers are kept separate from the records that get searched. Access, correction and erasure requests are handled as a process with an owner, and erasure reaches every store a record touched, including derived indexes.
Getting your data out
In placeExport is in open formats — CSV, XLSX, PDF and the original files you gave us — available on request and on exit, not as a paid migration. If you leave, you leave with everything, and we would rather agree that up front than negotiate it later.
Transmittal
Send us your security questionnaire
We will complete it. If your procurement process has a standard form, a supplier assurance pack or a set of clauses you need answered, send it over and we will fill it in properly rather than returning a brochure. If the honest answer to a question is "we do not do that yet", that is what you will get.
Send it overClause 5 · Exclusions
Where we are not yet
We hold no security certifications today. That is a gap in paperwork rather than in the controls described above — a certificate is an external audit we have not yet commissioned. We would rather say so plainly than imply otherwise. If a certification is a condition of working together, tell us early and we will give you an honest answer about whether the timeline works.
In the meantime the offer above is the practical answer: send your own questionnaire, clause set or supplier assurance pack and we will complete it properly. Where the answer is that we do not do something yet, that is the answer you will get.
Rev.This page describes what is in place today. It is reviewed quarterly, and anything we cannot evidence does not appear on it. Last reviewed 2026-09-27.