Trust centre
Trust centre
Where your data lives, who processes it, what we hold, and what we don't. Published in full, because your security reviewer will ask anyway.
01 · Certifications
What we hold — and what we don't.
Most vendors in this category publish nothing here. We'd rather state the position plainly than let you discover it in diligence.
SOC 2 Type II
Not yet held. Controls are being built against the criteria; we will publish the auditor and report date when the observation window closes. No interim claim.
ISO 27001
Not yet certified. The ISMS follows the standard's structure, but we do not claim certification we cannot produce a certificate for.
ISO 42001 (AI)
Not yet certified. Tracking it — it is becoming the AI-specific badge buyers ask for, and it maps closely to how the gateway already works.
GDPR
The standard plan is EU-hosted in Frankfurt, so processing sits inside the EU. A DPA is available on request.
Penetration testing
Not yet commissioned externally. When it is, we will publish the tester and the date, not a badge.
What this means
If you need a certificate today, we are not yet the right fit for that control — say so early and we will tell you straight rather than run you through a sales cycle.
02 · Sub-processors
Everyone who touches your data.
The full list for the standard EU-hosted plan. The on-prem edition uses none of these — it runs on your infrastructure.
| Sub-processor | Purpose | Region |
|---|---|---|
| Fly.io | Application compute and managed PostgreSQL | Frankfurt (EU) |
| Upstash | Redis — background job queue | EU |
| Cloudflare | CDN, DNS, WAF and R2 object storage for uploaded documents | EU / global edge |
| Anthropic | LLM inference for extraction, compliance and drafting | Per provider terms |
| Resend | Transactional email (notifications, approvals) | EU / US |
| Stripe | Subscription billing and payment processing | US / EU |
We will give 30 days' notice before adding a sub-processor that processes tender content.
03 · How the data is handled
The controls that actually exist.
We don't train on your data
Your tenders, requirements and pricing are never used to train models — ours or anyone's. This is a contractual term, not a preference.
Isolation is enforced by the database
PostgreSQL Row-Level Security with FORCE ROW LEVEL SECURITY on every tenant table. The app connects as a non-owner role with no BYPASSRLS, and the tenant is pinned inside each transaction.
Encryption
TLS in transit. Encryption at rest via the managed Postgres and R2 layers. Provider API keys are read from the environment and never written to the application database.
Human-in-the-loop
The AI drafts; a person approves. Every sign-off is recorded, timestamped and attributable — there is no path where a model's output ships unreviewed.
Append-only audit
AI calls, approvals and configuration changes are written to a log that can be read and added to, never quietly rewritten.
Your data leaves when you do
Projects, requirements, approvals and the audit trail export as one file. No exit interview, no support ticket.
Running a security review?
Start with the pre-answered questionnaire — it covers most of what a standard vendor assessment asks, so you can skip a round trip.