The spreadsheet that stalls the deal

Send the security questionnaire back today.

Every answer cites the approved policy it came from. Anything your evidence cannot prove is refused, with the gap named.

A decorative animation fills this screen: the documents of a policy library drifting at different depths. The sections below state what the product does in text.

00As it arrived from the buyer

acme_security_questionnaire.xlsx / 5 of 24 rows
GRC-01.1

Do you maintain a formal, approved information security program and policy reviewed at least annually?

Cited

Per Information Security Policy v3.2: Acme maintains a formal information security program governed by this policy, reviewed and approved annually by the CISO and executive leadership. The program is aligned to ISO/IEC 27001 control themes and covers all production systems and personnel.

POL-ISMS-001 v3.2 (para:2)
A&A-01.1

Do you hold a current SOC 2 Type II attestation? If yes, state the trust services criteria covered and period.

Cited

Per SOC 2 Type II Report (Security and Availability) v1.0: Acme holds a SOC 2 Type II attestation covering the Security and Availability trust services criteria, issued by Hollis & Marsh LLP for the twelve-month period ending 31 December 2025, with no exceptions noted. The report is available to customers under NDA via the trust portal.

CRT-SOC2-2025 v1.0 (para:2)
AIS-01.1

Has an independent penetration test of the application been performed in the last 12 months? Summarize scope and outcome.

Refused

RPT-PEN-2024 v1.0: EXPIRED 2025-06-10, cannot support a current-state claim

route to security@acme.example
DSP-01.1

Within how many days of contract termination is customer data deleted from your systems, including backups?

Refused

POL-RET-001: conflicting approved sources on a machine-checked assertion

route to owners for reconciliation
LGL-01.1

Will Vendor contractually commit to unlimited liability for any security breach and guarantee a 99.99% uptime SLA with financial penalties?

Routed to counsel

Question requests a contractual/legal commitment

outside answerable scope.
2 answered with citations / 3 refused or routed

01 / Try it yourself

Ask it anything
a buyer would ask.

sample evidence pack / no API call Replaying

Ask anything, or pick a question

Question

Is multi-factor authentication enforced for all workforce access to production systems?

CITED, GATE CLEAN
What the gates released
Per Access Control Policy v2.3: Access to production systems follows least privilege and role-based access control. Multi-factor authentication is mandatory for all workforce access to corporate and production environments, including VPN and SSO.
POL-AC-001 v2.3 para:2

02 / Why it refuses

Most tools answer confidently.
This one refuses correctly.

Gates are deterministic code that runs after the model, on the structure of your evidence.

Gate / certification evidence

The certification trap

Is your ISMS ISO 27001 certified?

What a confident tool ships Yes. Our ISMS is ISO 27001 certified. Refused

Your evidence holds a certification roadmap, not a certificate. A plan is not an attestation, so the answer never ships.

Sources conflictThe contradiction trap

Two approved policies give different deletion windows, 90 days and 365 days, and both are real. The gate quarantines both sources and routes the question to both owners. Any other question citing the tainted policy refuses too.

Evidence expiredThe staleness trap

The penetration test report expired before the question arrived. Expired evidence cannot support a present tense claim, so the refusal carries the document, its expiry date and the owner to chase.

Routed to counselThe commitment trap

A demand for unlimited liability never reaches the model. Contract commitments are detected and routed to legal before drafting, so there is no draft for a reviewer to rubber stamp.

167tests on every commit 11adversarial evals gate release 4traps planted in every run 0uncited answers released MITengine, open source

03 / See it run

One run, start to finish.

recorded from the browser, unedited footage

04 / What you get

Proof you can break
with your own hands.

gate

Do you enforce multi factor authentication for administrative access?

Per Access Control Policy v2.3: administrative access requires MFA.

Is your information security management system ISO 27001 certified?

Roadmap is not a certificate. No attestation on file.

Is customer data encrypted in transit using TLS 1.2 or higher?

Per Cryptography Policy v1.4: TLS 1.2 is the enforced minimum.

Has an independent penetration test been performed in the last 12 months?

RPT-PEN-2024 expired 2025-06-10, cannot support a current claim.

Within how many days of termination is customer data deleted?

Two approved sources disagree. Held until an owner reconciles.

Do you maintain a formal, approved information security policy?

Per Information Security Policy v3.2: reviewed at least annually.

0 cited 0 refused Drag a question across the gate

An interactive animation: security questionnaire questions drift across a gate. What the approved evidence supports comes out cited; what it cannot comes out refused with the gap named. Each card can be dragged or arrow-keyed across the gate and back. The deliverables listed below state the same outcomes in text.

Change one name. Every hash covers the event before it, so the chain breaks from there and cannot be repaired by anything downstream.

01 / RECEIVED69a66f75765f4b
02 / ROUTEDf56ed86689f52b
03 / EVIDENCE SCAN2d938041ee227b
04 / DRAFTEDb067f9e20fa33b
05 / APPROVEDfce3d05c4f02ef
06 / DRAFTEDc27803d5a95d77
Chain verifies, all six links intact

Editing needs JavaScript. Each event's hash covers the event plus the previous hash, so no historical edit survives verification.

run_report.html
The Constat run report: a sixty percent coverage dial, a lattice of ten question verdicts, and tiles reading ten questions ingested, forty percent refused by design, and a valid audit chain.
/review
The Constat review queue, showing answers held for a named human reviewer with fields for the reviewer name and note.
/workspace
The Constat workspace, listing uploaded evidence documents with their approval status and a control to start a run.

05 / Where your documents go

What leaves your infrastructure.

  • Your documentsstay in your workspace, hard deleted after 14 days
  • What crossesone question plus four excerpts, never a whole document
  • Sub-processorsGoogle Gemini drafts, Render hosts, no others
Demo

Our key

Free. Public evidence only.

Why public only

Google may use free tier content to improve their services. A published SOC 2 report loses nothing by that; your confidential runbooks would.

BYOK

Your key

Your provider, your contract terms.

Who this is for

Confidential evidence. The only party who can promise you anything about your text is the provider you already pay.

Managed

Our paid key

No-training commitment, in contract.

What becomes negotiable

Retention, residency and the no-training commitment become contract terms rather than marketing lines.

06 / Get early access

The hosted workspace opens shortly

It is built and tested, and it opens to early users first. One message reserves your place.

Tell me which one you are

Pick the line that fits. It copies, then opens LinkedIn, and it tells me what you need before I reply.

Nothing is sent automatically. You paste it yourself.

Run the engine yourself instead

Open source, MIT, evidence included. Two commands on your own machine:

python3 -m venv .venv && .venv/bin/pip install pytest openpyxl
.venv/bin/python run_demo.py

Read the source on GitHub

Hi Dhruv, I found Constat. We answer security questionnaires and I want to try it on ours. Can we talk about a pilot?

Hi Dhruv, I read the Constat data handling section. I have a question about where evidence goes and what the BYOK tier would look like for us.

Hi Dhruv, I tried the Constat demo. I am interested in how the gates and the audit chain work rather than buying anything right now.

The documents, in full. Founder drafted, pending review by counsel.

Terms of use
Founder drafted, pending legal review This document was written by the founder, not by a lawyer, and has not been through legal review. It is published in this state deliberately: a pre-launch demo that collects documents should say what it does with them from the first day rather than from the day it can afford counsel. Where it is wrong it will be corrected, and material changes will be dated here. If anything below matters to your decision, ask and you will get a straight answer in writing.

1. Who you are contracting with

The service at this address is Constat, operated by Dhruv Shahi, an individual operator based in India. There is no company entity behind it yet. Governing law and the venue for any dispute are the laws of India. This document was drafted by the operator rather than by counsel, so if you need contractual certainty, ask before you rely on this service, and expect a reviewed agreement before any paid tier is sold to you.

2. This is a demo, and it is sold as one

Constat is pre-launch. It is provided as is and as available, with no warranty of any kind, express or implied, including any warranty of merchantability, fitness for a particular purpose, accuracy or non infringement. There is no service level agreement, no uptime commitment, no support commitment and no guarantee of continuity. The service may change, break or be withdrawn without notice, and a workspace may be deleted early if the demo is being abused or if it costs more to run than the operator can carry.

Nothing this service outputs is legal, audit or compliance advice. Every answer it drafts is a draft. The whole design of the product is that a named human reviews before anything is released, and that design assumes you actually do the reviewing. If you send a Constat answer to a customer without reading it, that is your representation to your customer, not ours.

3. What you may upload

On the free demo tier, drafting runs on Google Gemini's free tier, whose terms permit Google to use submitted content to improve their services. So the rule for this tier is simple and you agree to it by uploading:

  • Upload public evidence only. A published SOC 2 report, an ISO certificate, trust-center policies, anything you would be comfortable seeing outside your company.
  • Do not upload confidential, personal or regulated data. No customer data, no personal data of third parties, no secrets, no material non-public information.
  • Do not upload anything you do not have the right to upload.
  • Do not use the service to break the law, to attack it or anyone else, or to generate misleading claims about your security posture.

If you need to run Constat over confidential evidence, that is the BYOK tier, where you supply your own provider key and your text travels under your contract with that provider. Ask for it. It is not built yet, and saying so is more useful to you than a checkbox that pretends otherwise.

4. Your material stays yours

You keep all right, title and interest in the documents you upload and in the answers produced from them. We claim no ownership of your intellectual property and no licence to it beyond what is technically required to run the service you asked for: storing the document in your workspace, indexing it so it can be retrieved, sending a question and the retrieved excerpts to the drafting model, and generating your report and workbook. We do not sell, licence or share your documents. We do not use them to train anything of ours; note that this is a statement about us and not about Google, whose free-tier terms are described above and on the privacy page.

5. Limits on the free tier

  • Three runs per workspace.
  • Twenty documents per workspace, five megabytes per file.
  • Three signups per network per day.
  • The workspace and everything in it is hard deleted fourteen days after signup.

Your workspace link is the only credential. There is no password and no reset. If you lose the link you lose the workspace, and we cannot recover it for you, because the link is the capability and we store only a hash of it.

6. Liability

To the maximum extent the law allows, the operator is not liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost data or business interruption, arising from your use of this demo. Total aggregate liability for any claim relating to the free tier is limited to the amount you paid for it, which is nothing. Some jurisdictions do not allow these exclusions, in which case they apply only as far as that jurisdiction permits.

7. Ending it

You can stop using the service at any time, and you can ask for your workspace to be deleted immediately rather than waiting for the fourteen day sweep. The operator may suspend or delete a workspace that breaks section 3, that threatens the service, or that makes the demo unaffordable to run.

8. Changes and contact

These terms will change, because the product is early. Material changes will be dated at the top of this page. The fastest way to reach the operator is a LinkedIn message. Formal requests, including corrections and deletions, can also go to dhruv.shahi07@gmail.com, and are answered by a person.

Privacy and data handling
Founder drafted, pending legal review This document was written by the founder, not by a lawyer, and has not been through legal review. It is published in this state deliberately: a pre-launch demo that collects documents should say what it does with them from the first day rather than from the day it can afford counsel. Where it is wrong it will be corrected, and material changes will be dated here. If anything below matters to your decision, ask and you will get a straight answer in writing.

Short version, because the long version below only exists so this one is checkable: we collect your organization name, an email address, your IP address and whatever text is in the documents you upload. We keep uploads for fourteen days and then hard delete them. Two sub-processors, Google and Render, and no others. One cookie, which logs you in and does nothing else. No analytics, no trackers, no advertising pixels, on any page of this site.

Data handling

What we collect, and why

WhatWhyHow long
Organization nameNames your workspace and titles the generated questionnaire and report.Kept after workspace deletion, in the signup record.
Email addressIdentifies the signup, lets us contact you about the demo, and is offered as the default document owner on the upload form. We do not send the workspace link by email and we do not run a mailing list.Kept after workspace deletion, in the signup record.
IP addressRate limiting only. Three signups per network per day is the only thing standing between this demo and an unpaid API bill.Deleted after seven days.
Uploaded documents and their extracted textRetrieval and drafting. This is the product.Hard deleted fourteen days after signup, with the whole workspace directory.
Run outputs (report, workbook, audit log)The deliverables you came for.Deleted with the workspace at fourteen days; older run directories are pruned sooner, keeping the newest five.
Reviewer name and noteNamed review is the point of the audit chain. You type the name yourself; in the demo it is self attested and unverified. Stored in the approvals record, which is not swept with the workspace.
Run metadata (identifiers, timings, counts, error text) Operating the queue and debugging failures.Retained.
Server logsWritten to the host's log stream for operations. They contain request lines and client addresses.Held by the host under its own retention.

We do not ask for and do not want special category personal data, payment details or credentials. If you upload them by mistake, email us and we will delete the workspace immediately rather than waiting for the sweep.

The free tier reality, in one sentence

Drafting on this demo runs on Google Gemini's free tier, whose terms allow Google to use submitted content to improve their services, which is why this tier asks you to upload public evidence only and why we make no no-training claim on your behalf.

We used to write "never used for training" on the landing page. It was true of us and misleading about the stack, so it is gone. What is accurate: we do not train on your documents, and on this tier we cannot make that promise for the model provider. The BYOK tier exists so that promise comes from the provider you already have a contract with, and the Managed tier exists so it comes from a paid tier that carries it in writing.

Sub-processors

WhoWhat they doWhat they receive
Google (Gemini API)Drafts each answer.One question and the excerpts retrieved for it, per answer. Never your full documents, never your document list, never another tenant's material.
RenderHosts the server and the disk your workspace sits on.Everything stored, as any host does, plus request logs.

There are no other sub-processors. No analytics vendor, no error tracking vendor, no CDN, no email service provider, no third party retrieval or indexing service. If that list ever grows, it grows on this page first.

Where processing happens

Retrieval, indexing, the gates, the audit chain and every generated file are produced on our own server. The only outbound call in a run is the drafting call to Google. Tenants are structurally isolated: each workspace has its own directory and its own index, and the retrieval layer is rooted inside it rather than filtered after the fact.

Cookies

One cookie, tt_<workspace>, set the first time you open your workspace link. It is strictly necessary: it is what keeps you signed in to that workspace. It is HttpOnly, SameSite=Lax, Secure, scoped to your workspace path, and expires after fourteen days. There are no analytics cookies, no advertising cookies and no third party scripts of any kind on this site, which is why you were never shown a cookie banner. That is a deliberate product decision and a difference worth noticing when you compare this to the other tools in this category.

Your rights

Whatever framework applies to you, the practical answer is the same and does not require a form:

  • Access: ask and we will tell you exactly what is stored against your workspace.
  • Deletion: ask and the workspace and all its files are deleted immediately. Otherwise it happens automatically at fourteen days.
  • Correction: ask, or just re-upload.
  • Objection and portability: your documents are your documents; everything the run produced is downloadable from your workspace while it exists.
  • Complaint: the operator is in India, so the Digital Personal Data Protection Act 2023 governs and the Data Protection Board of India is the body to complain to. If you are in the EU or UK, the GDPR rights above apply to you as well and you may complain to your own national supervisory authority instead.

Requests go to dhruv.shahi07@gmail.com, or by LinkedIn message if that is easier. They are read by one person, which in practice means a same week answer, not a ticket number.

Children

This is a business tool and is not directed at anyone under 16.

Security, honestly

Your workspace link is a bearer capability: anyone holding it holds the workspace. We store only a hash of it. There is no password, no multi-factor authentication and no session management beyond that cookie, because this is a demo. Treat the link like a password, and do not put evidence in this tier that would hurt you if the link leaked.