TRUST & SECURITY

A verification company
you can verify.

We sell proof, so we hold ourselves to the same standard: plain commitments, honest certification status, and nothing that depends on you taking our word for it.

01COMMITMENTS
T1Your artefacts train nothing

Documents submitted for checking are processed for verification only. They are never used to train models — ours or anyone else's — and never shared. This is a contractual commitment in every pilot agreement, not a settings toggle.

T2Deterministic by design

Verdicts come from encoded rules, not model sampling. That is a security property as much as a product one: the same artefact cannot quietly produce a different verdict tomorrow, and every verdict is reproducible on demand.

T3Tamper-evident records

Every check run is hashed (SHA-256) and chained to the previous record. Any retroactive edit breaks every subsequent hash, visibly. Receipts contain hashes, not your content — they cannot be reversed into your documents.

T4Encryption and hosting

All traffic is TLS-encrypted in transit. The site and API are hosted on Vercel infrastructure; transactional email runs through Resend; analytics through PostHog (EU hosting). We keep the processor list short and current on our privacy page.

T5Least-data by default

We collect the minimum needed to run a check and respond to you. Pilot enquiries are deleted after 24 months of inactivity. Erasure requests: one email, actioned within a month.

02CERTIFICATION STATUS

Where we are, stated plainly.

We are an early-stage company and we will not pretend otherwise with borrowed badges. This table is the current truth and it will be kept current.

TLS in transit · hash-chained recordsLIVE
Written DPA for every pilotLIVE
SOC 2 Type IPLANNED · POST-FUNDING
ISO 27001ROADMAP
Independent penetration testPLANNED · PRE-GA

Found a security issue?

Report it to satyawansingh82@hotmail.com with “SECURITY” in the subject. We acknowledge within 48 hours and won't pursue good-faith researchers.

Report an issue