Security
Security is a feature, not a PDF.
How we're different
- Ops-first, not checks-first.
- Policy-gated actions with human approvals.
- Evidence binders by default.
Trust rule: AI drafts; humans decide for sensitive outcomes.
Controls snapshot
Encryption
- HTTPS in transit
- Encrypted storage at rest (deployment dependent)
- SHA-256 hashing for uploaded artifacts
Access
- Role-based access control (RBAC)
- Least privilege by default
- Admin-only configuration surfaces
Auditability
- Append-only case timeline
- Evidence binder export (PDF + JSON)
- Approval history captured and exported
Operational safety
- Policy-gated actions for external comms
- Human approvals for sensitive outcomes
- Deterministic requirements checklist
Architecture (plain English)
Email + intake
Workflow
Policy gates
Evidence binder
Audit exports
Security packet
Mock overview of controls, policies, and posture.
Download Security Packet (PDF)Looking for vendor risk answers? See Procurement pack.
Compliance posture aligned with SOC 2 controls (hypothetical roadmap). Not legal advice.