Trust Center

Everything we claim.
And everything we don't — yet.

Our full posture, in the labels our engineers use: shipped, in progress, roadmap.

The two AI guarantees

Enforced below the modules — immune to admin settings and API parameters.

Cite-or-fallback. Not configurable.

Every AI output cites retrievable evidence or returns "insufficient evidence — human input required." No setting, flag or API parameter can turn this off.

A human always commits the record.

AI drafts, suggests and scores — it never commits a record. A qualified person reviews and e-signs, with name, time, meaning and reason captured.

Your evidenceSOPs · logs · responsesretrievesAI Gatewayone door · fully loggedredaction · no trainingcan cite?Draft, with citationsevery claim → a sourcecan't?“Insufficient evidence”it stops — no guessing✍ human signs
Every AI request passes one gateway. The output cites its sources or admits it can't — and only a person's e-signature turns it into a record.

The life of one file

Follow a supplier's SOP upload from their browser to a sealed audit record.

01

In transit

Uploaded over TLS 1.3 through a tokenized guest link — scoped to one audit, revocable any time.

02

At rest

Stored encrypted in your tenant’s isolated space, in the region you elected — India, US or EU. Four layers enforce isolation.

03

Sealed

A SHA-256 fingerprint binds the file to the audit record. Any later change breaks the seal — visibly, for an inspector.

04

Signed

Signatures capture who, when, meaning and reason — bound to the sealed version, invalid if the record shifts.

05

Exit-ready

Full export in 7 business days; deletion with signed certificate in 30. Never used to train models.

What we enforce today

Part-11-grade AI traceability

Every AI call logs model version, prompt hash, retrieval set, confidence and reviewer disposition — queryable in one step, months later.

Tamper-evident audit trail

Every state change writes an append-only, SHA-256-hashed row — user, UTC, session, reason. No role can disable it.

No third party in the AI path

The multi-LLM gateway (Anthropic, OpenAI, Gemini, local path) is built in-house. Nobody sits between your data and the model.

Zero training on your data

Contractual default: your data never trains models. Provider opt-outs enforced; no-training certification issuable under the DPA.

Tenant isolation, four layers deep

Route middleware, service guards, query helpers and cross-tenant CI tests enforce isolation. Cross-tenant access requires explicit, consented affiliation.

Your data, your region, your exit

Residency elected at provisioning (India, US, EU). Full export within 7 business days; deletion with signed certificate within 30.

Compliance & security posture

Our own labels, kept current. 'In progress' and 'roadmap' mean exactly that — timelines under NDA.

GAMP 5 Category 4 configured product

Commitment

Same classification as the enterprise incumbents; ~60% less validation effort than Cat 5 bespoke. Validation Accelerator Package included, never an upsell.

21 CFR Part 11 · EU GMP Annex 11 · ALCOA+

Designed-in

E-signatures capture password + meaning + reason on every signing. Self-assessed matrices under NDA; customer-led validation supported.

SOC 2 Type I

In progress

Controls self-assessed today; attestation timeline shared under NDA.

SAML SSO & MFA

Roadmap

OIDC sign-in today; SAML and TOTP MFA on the security roadmap.

Encryption & keys

Shipped

TLS 1.3 in transit, AES-256 at rest, BYOK on Enterprise.

The honesty register, in public.

Things we deliberately do not claim: we are not blockchain (the audit trail is tamper-evident — SHA-256 hashing, append-only); AI self-improvement is measured today, not automated; the remote-audit cockpit and fine-tuned in-house model are roadmap; e-signature hard enforcement is being rolled out as the production default. If a vendor tells you everything is done, ask them for this list.

Send us your vendor assessment questionnaire.

Pre-filled answers, compliance matrices and the validation package — under NDA.