The certification trap
Is your ISMS ISO 27001 certified?
Your evidence holds a certification roadmap, not a certificate. A plan is not an attestation, so the answer never ships.
Every answer cites the approved policy it came from. Anything your evidence cannot prove is refused, with the gap named.
A decorative animation fills this screen: the documents of a policy library drifting at different depths. The sections below state what the product does in text.
00As it arrived from the buyer
Do you maintain a formal, approved information security program and policy reviewed at least annually?
Per Information Security Policy v3.2: Acme maintains a formal information security program governed by this policy, reviewed and approved annually by the CISO and executive leadership. The program is aligned to ISO/IEC 27001 control themes and covers all production systems and personnel.
POL-ISMS-001 v3.2 (para:2)Do you hold a current SOC 2 Type II attestation? If yes, state the trust services criteria covered and period.
Per SOC 2 Type II Report (Security and Availability) v1.0: Acme holds a SOC 2 Type II attestation covering the Security and Availability trust services criteria, issued by Hollis & Marsh LLP for the twelve-month period ending 31 December 2025, with no exceptions noted. The report is available to customers under NDA via the trust portal.
CRT-SOC2-2025 v1.0 (para:2)Has an independent penetration test of the application been performed in the last 12 months? Summarize scope and outcome.
RPT-PEN-2024 v1.0: EXPIRED 2025-06-10, cannot support a current-state claim
route to security@acme.exampleWithin how many days of contract termination is customer data deleted from your systems, including backups?
POL-RET-001: conflicting approved sources on a machine-checked assertion
route to owners for reconciliationWill Vendor contractually commit to unlimited liability for any security breach and guarantee a 99.99% uptime SLA with financial penalties?
Question requests a contractual/legal commitment
outside answerable scope.01 / Try it yourself
Ask anything, or pick a question
Is multi-factor authentication enforced for all workforce access to production systems?
02 / Why it refuses
Gates are deterministic code that runs after the model, on the structure of your evidence.
Is your ISMS ISO 27001 certified?
Your evidence holds a certification roadmap, not a certificate. A plan is not an attestation, so the answer never ships.
Two approved policies give different deletion windows, 90 days and 365 days, and both are real. The gate quarantines both sources and routes the question to both owners. Any other question citing the tainted policy refuses too.
The penetration test report expired before the question arrived. Expired evidence cannot support a present tense claim, so the refusal carries the document, its expiry date and the owner to chase.
A demand for unlimited liability never reaches the model. Contract commitments are detected and routed to legal before drafting, so there is no draft for a reviewer to rubber stamp.
03 / See it run
04 / What you get
Do you enforce multi factor authentication for administrative access?
Per Access Control Policy v2.3: administrative access requires MFA.
Is your information security management system ISO 27001 certified?
Roadmap is not a certificate. No attestation on file.
Is customer data encrypted in transit using TLS 1.2 or higher?
Per Cryptography Policy v1.4: TLS 1.2 is the enforced minimum.
Has an independent penetration test been performed in the last 12 months?
RPT-PEN-2024 expired 2025-06-10, cannot support a current claim.
Within how many days of termination is customer data deleted?
Two approved sources disagree. Held until an owner reconciles.
Do you maintain a formal, approved information security policy?
Per Information Security Policy v3.2: reviewed at least annually.
An interactive animation: security questionnaire questions drift across a gate. What the approved evidence supports comes out cited; what it cannot comes out refused with the gap named. Each card can be dragged or arrow-keyed across the gate and back. The deliverables listed below state the same outcomes in text.
Change one name. Every hash covers the event before it, so the chain breaks from there and cannot be repaired by anything downstream.
Editing needs JavaScript. Each event's hash covers the event plus the previous hash, so no historical edit survives verification.
05 / Where your documents go
Free. Public evidence only.
Google may use free tier content to improve their services. A published SOC 2 report loses nothing by that; your confidential runbooks would.
Your provider, your contract terms.
Confidential evidence. The only party who can promise you anything about your text is the provider you already pay.
No-training commitment, in contract.
Retention, residency and the no-training commitment become contract terms rather than marketing lines.
06 / Get early access
It is built and tested, and it opens to early users first. One message reserves your place.
Pick the line that fits. It copies, then opens LinkedIn, and it tells me what you need before I reply.
Nothing is sent automatically. You paste it yourself.
Open source, MIT, evidence included. Two commands on your own machine:
python3 -m venv .venv && .venv/bin/pip install pytest openpyxl
.venv/bin/python run_demo.py
Hi Dhruv, I found Constat. We answer security questionnaires and I want to try it on ours. Can we talk about a pilot?
Hi Dhruv, I read the Constat data handling section. I have a question about where evidence goes and what the BYOK tier would look like for us.
Hi Dhruv, I tried the Constat demo. I am interested in how the gates and the audit chain work rather than buying anything right now.
The documents, in full. Founder drafted, pending review by counsel.
The service at this address is Constat, operated by Dhruv Shahi, an individual operator based in India. There is no company entity behind it yet. Governing law and the venue for any dispute are the laws of India. This document was drafted by the operator rather than by counsel, so if you need contractual certainty, ask before you rely on this service, and expect a reviewed agreement before any paid tier is sold to you.
Constat is pre-launch. It is provided as is and as available, with no warranty of any kind, express or implied, including any warranty of merchantability, fitness for a particular purpose, accuracy or non infringement. There is no service level agreement, no uptime commitment, no support commitment and no guarantee of continuity. The service may change, break or be withdrawn without notice, and a workspace may be deleted early if the demo is being abused or if it costs more to run than the operator can carry.
Nothing this service outputs is legal, audit or compliance advice. Every answer it drafts is a draft. The whole design of the product is that a named human reviews before anything is released, and that design assumes you actually do the reviewing. If you send a Constat answer to a customer without reading it, that is your representation to your customer, not ours.
On the free demo tier, drafting runs on Google Gemini's free tier, whose terms permit Google to use submitted content to improve their services. So the rule for this tier is simple and you agree to it by uploading:
If you need to run Constat over confidential evidence, that is the BYOK tier, where you supply your own provider key and your text travels under your contract with that provider. Ask for it. It is not built yet, and saying so is more useful to you than a checkbox that pretends otherwise.
You keep all right, title and interest in the documents you upload and in the answers produced from them. We claim no ownership of your intellectual property and no licence to it beyond what is technically required to run the service you asked for: storing the document in your workspace, indexing it so it can be retrieved, sending a question and the retrieved excerpts to the drafting model, and generating your report and workbook. We do not sell, licence or share your documents. We do not use them to train anything of ours; note that this is a statement about us and not about Google, whose free-tier terms are described above and on the privacy page.
Your workspace link is the only credential. There is no password and no reset. If you lose the link you lose the workspace, and we cannot recover it for you, because the link is the capability and we store only a hash of it.
To the maximum extent the law allows, the operator is not liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, arising from your use of this demo. Total aggregate liability for any claim relating to the free tier is limited to the amount you paid for it, which is nothing. Some jurisdictions do not allow these exclusions, in which case they apply only as far as that jurisdiction permits.
You can stop using the service at any time, and you can ask for your workspace to be deleted immediately rather than waiting for the fourteen day sweep. The operator may suspend or delete a workspace that breaks section 3, that threatens the service, or that makes the demo unaffordable to run.
These terms will change, because the product is early. Material changes will be dated at the top of this page. The fastest way to reach the operator is a LinkedIn message. Formal requests, including corrections and deletions, can also go to dhruv.shahi07@gmail.com, and are answered by a person.
Short version, because the long version below only exists so this one is checkable: we collect your organization name, an email address, your IP address and whatever text is in the documents you upload. We keep uploads for fourteen days and then hard delete them. Two sub-processors, Google and Render, and no others. One cookie, which logs you in and does nothing else. No analytics, no trackers, no advertising pixels, on any page of this site.
| What | Why | How long |
|---|---|---|
| Organization name | Names your workspace and titles the generated questionnaire and report. | Kept after workspace deletion, in the signup record. |
| Email address | Identifies the signup, lets us contact you about the demo, and is offered as the default document owner on the upload form. We do not send the workspace link by email and we do not run a mailing list. | Kept after workspace deletion, in the signup record. |
| IP address | Rate limiting only. Three signups per network per day is the only thing standing between this demo and an unpaid API bill. | Deleted after seven days. |
| Uploaded documents and their extracted text | Retrieval and drafting. This is the product. | Hard deleted fourteen days after signup, with the whole workspace directory. |
| Run outputs (report, workbook, audit log) | The deliverables you came for. | Deleted with the workspace at fourteen days; older run directories are pruned sooner, keeping the newest five. |
| Reviewer name and note | Named review is the point of the audit chain. You type the name yourself; in the demo it is self attested and unverified. | Stored in the approvals record, which is not swept with the workspace. |
| Run metadata (identifiers, timings, counts, error text) | Operating the queue and debugging failures. | Retained. |
| Server logs | Written to the host's log stream for operations. They contain request lines and client addresses. | Held by the host under its own retention. |
We do not ask for and do not want special category personal data, payment details or credentials. If you upload them by mistake, email us and we will delete the workspace immediately rather than waiting for the sweep.
Drafting on this demo runs on Google Gemini's free tier, whose terms allow Google to use submitted content to improve their services, which is why this tier asks you to upload public evidence only and why we make no no-training claim on your behalf.
We used to write "never used for training" on the landing page. It was true of us and misleading about the stack, so it is gone. What is accurate: we do not train on your documents, and on this tier we cannot make that promise for the model provider. The BYOK tier exists so that promise comes from the provider you already have a contract with, and the Managed tier exists so it comes from a paid tier that carries it in writing.
| Who | What they do | What they receive |
|---|---|---|
| Google (Gemini API) | Drafts each answer. | One question and the excerpts retrieved for it, per answer. Never your full documents, never your document list, never another tenant's material. |
| Render | Hosts the server and the disk your workspace sits on. | Everything stored, as any host does, plus request logs. |
There are no other sub-processors. No analytics vendor, no error tracking vendor, no CDN, no email service provider, no third party retrieval or indexing service. If that list ever grows, it grows on this page first.
Retrieval, indexing, the gates, the audit chain and every generated file are produced on our own server. The only outbound call in a run is the drafting call to Google. Tenants are structurally isolated: each workspace has its own directory and its own index, and the retrieval layer is rooted inside it rather than filtered after the fact.
One cookie, tt_<workspace>, set the first time you open your workspace link. It is strictly necessary: it is what keeps you signed in to that workspace. It is HttpOnly, SameSite=Lax, Secure, scoped to your workspace path, and expires after fourteen days. There are no analytics cookies, no advertising cookies and no third party scripts of any kind on this site, which is why you were never shown a cookie banner. That is a deliberate product decision and a difference worth noticing when you compare this to the other tools in this category.
Whatever framework applies to you, the practical answer is the same and does not require a form:
Requests go to dhruv.shahi07@gmail.com, or by LinkedIn message if that is easier. They are read by one person, which in practice means a same week answer, not a ticket number.
This is a business tool and is not directed at anyone under 16.
Your workspace link is a bearer capability: anyone holding it holds the workspace. We store only a hash of it. There is no password, no multi-factor authentication and no session management beyond that cookie, because this is a demo. Treat the link like a password, and do not put evidence in this tier that would hurt you if the link leaked.