A company selling decision assurance should be willing to be examined on the same terms. This page sets out how we handle evidence, what standards we align to, what we claim, and what we do not.
Each governed verdict is preserved with its outcome, stated confidence, the evidence relied upon, the governing policy, and the accountable authority.
Records are written so that later alteration is detectable. A record that could be quietly edited has no value in an audit or a proceeding.
A verdict can be reconstructed as it stood at the time it was issued, rather than as the system would answer today.
The evidence record belongs to the customer, is exportable, and is retained on the customer's schedule, not ours.
Assurance is only useful if it speaks the language of the obligation. We maintain mappings from the decision record to the evidence expectations of the frameworks below, and we distinguish alignment from certification everywhere on this site.
Framework names are used to describe the obligations we help customers evidence. Certification status, where applicable, is provided under NDA in the diligence package rather than asserted here.
Data is processed to reach and evidence a verdict. It is not used to train general models on customer or consumer content.
Household, elder, and minor contexts carry stricter handling, explicit consent expectations, and narrower escalation paths.
Deployment options cover regional residency and tenant isolation requirements. Specifics are confirmed in the security review for each engagement.
Security findings can be reported directly to our team. We acknowledge, triage, and report back on a stated timeline.
Security questionnaires, architecture review under NDA, data processing terms, and current certification status are provided to prospective customers and partners through the diligence package.