Get in touch

Our own security answers, produced by our own engine.

Every answer below was generated by the system this page describes, from our own evidence corpus, under the same gates that run for a customer. Nothing here was written by hand. Questions our evidence cannot support are listed as open rather than answered with something plausible — which is the entire argument, applied to ourselves.

61%answered self-serve
14with citations
9open — ask us
23standard questions
How to read this page. An answer appears only when every claim in it is supported by an approved, in-force document, and it names that document, its version and the paragraph. We hold no certifications, so every certification question below is refused — including ISO 42001, where the only document on file is a roadmap, and a roadmap is not a certificate.
Security program
Do you maintain a formal, approved information security program and policy?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Audit and assurance
Do you hold a current SOC 2 Type II attestation?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Is your organization ISO/IEC 27001 certified?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Are you certified to ISO/IEC 42001 for AI management systems?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Has an independent penetration test been performed in the last 12 months?
Per Platform Security Standard v1.0: Known gaps. No independent penetration test has been performed. Workspace identifiers are derived from the organisation name and are therefore guessable, which discloses that a workspace exists to anyone who guesses it; access still requires a valid token bound to that workspace.…
STD-PLAT-001 · v1.0 · para:9
Identity and access
How is access to a customer workspace authenticated?
Per Authentication and Workspace Access Standard v1.0: # Authentication and Workspace Access Standard
STD-AUTH-001 · v1.0 · para:1
STD-ISO-001 · v1.0 · para:2
How are access tokens stored, and can they be recovered from your database?
Per Authentication and Workspace Access Standard v1.0: Access to a workspace requires a bearer token. Tokens take the form `t.<slug>.<random>` and carry 192 bits of entropy generated by the platform's cryptographic random source. A token is displayed once, at issue, and is never stored anywhere in recoverable form.
STD-AUTH-001 · v1.0 · para:2
STD-PLAT-001 · v1.0 · para:7
Data handling
How long do you retain uploaded customer documents, and how are they deleted?
Per Customer Data Use and Model Training Policy v1.0: Three key modes, with different guarantees, stated plainly because they are not equivalent. In demo mode the platform's own free-tier key is used and only public evidence may be uploaded, because free-tier terms permit the provider to use submitted content to improve their servic…
POL-DATA-001 · v1.0 · para:4
POL-RET-001 · v1.0 · para:2
What customer data leaves our infrastructure when an answer is drafted?
Per Customer Data Use and Model Training Policy v1.0: What crosses the boundary. When an answer is drafted, exactly one question and at most four retrieved excerpts are sent to the model provider. A whole document is never transmitted. Documents themselves remain in the customer's workspace.
POL-DATA-001 · v1.0 · para:3
LST-SUB-001 · v1.0 · para:3
Which subprocessors process customer data?
Per Customer Data Use and Model Training Policy v1.0: # Customer Data Use and Model Training Policy
POL-DATA-001 · v1.0 · para:1
What personal data does the service store?
Per Data Retention and Deletion Policy v1.0: Personal data. The platform stores the email address used to create a workspace and the hash of that workspace's access token. It stores no other personal data, no payment details and no behavioural profile.
POL-RET-001 · v1.0 · para:5
AI governance
Do you use customer data to train, fine-tune or improve any model?
Per Customer Data Use and Model Training Policy v1.0: # Customer Data Use and Model Training Policy
POL-DATA-001 · v1.0 · para:1
What data can your models access, and what are the boundaries on that access?
Per Model and Data Access Boundary Standard v1.0: # Model and Data Access Boundary Standard
STD-MODEL-001 · v1.0 · para:1
POL-RET-001 · v1.0 · para:5
How is a human kept in the loop over AI-generated output?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
How does the system resist prompt injection?
Per Prompt Injection Resistance Standard v1.0: # Prompt Injection Resistance Standard
STD-INJ-001 · v1.0 · para:1
Do you have an AI governance policy, and what does it require?
Per AI Governance Policy v1.0: # AI Governance Policy
POL-AIGOV-001 · v1.0 · para:1
PLN-ISO42001 · v0.2 · para:6
How is data leakage between tenants prevented?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Product security
How is output encoded to prevent cross-site scripting?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
How are file uploads bounded and validated?
Per Platform Security Standard v1.0: Upload handling. Uploads are bounded in size before they are read, extraction is bounded in time and in extracted length, and only a fixed set of file types is accepted. Text extraction runs in-process with no shell invocation.
STD-PLAT-001 · v1.0 · para:3
What security headers does the application serve?
Per Platform Security Standard v1.0: Transport and headers. The hosted application is served over TLS with strict transport security, content type sniffing disabled, framing denied, and a content security policy that forbids inline script.
STD-PLAT-001 · v1.0 · para:4
Resilience
What is your availability posture and do you offer an uptime commitment?
Per Platform Security Standard v1.0: Availability posture, stated rather than implied. The application runs as a single instance because the run queue and the local database are single-process components. There is no high-availability configuration, no automatic failover and no uptime commitment. Scaling beyond one …
STD-PLAT-001 · v1.0 · para:8
Logging
Are audit logs protected from tampering?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Vulnerability management
Have you had an independent security assessment, and what are your known gaps?
Not published — our evidence does not support a self-serve answer. Ask us through security review.
Constat · page generated 2026-08-25 · back to the product
All customer data shown anywhere on this site is synthetic.