Trust centre

Trust centre

Where your data lives, who processes it, what we hold, and what we don't. Published in full, because your security reviewer will ask anyway.

01 · Certifications

What we hold — and what we don't.

Most vendors in this category publish nothing here. We'd rather state the position plainly than let you discover it in diligence.

SOC 2 Type II

Not yet held. Controls are being built against the criteria; we will publish the auditor and report date when the observation window closes. No interim claim.

ISO 27001

Not yet certified. The ISMS follows the standard's structure, but we do not claim certification we cannot produce a certificate for.

ISO 42001 (AI)

Not yet certified. Tracking it — it is becoming the AI-specific badge buyers ask for, and it maps closely to how the gateway already works.

GDPR

The standard plan is EU-hosted in Frankfurt, so processing sits inside the EU. A DPA is available on request.

Penetration testing

Not yet commissioned externally. When it is, we will publish the tester and the date, not a badge.

What this means

If you need a certificate today, we are not yet the right fit for that control — say so early and we will tell you straight rather than run you through a sales cycle.

02 · Sub-processors

Everyone who touches your data.

The full list for the standard EU-hosted plan. The on-prem edition uses none of these — it runs on your infrastructure.

Sub-processorPurposeRegion
Fly.ioApplication compute and managed PostgreSQLFrankfurt (EU)
UpstashRedis — background job queueEU
CloudflareCDN, DNS, WAF and R2 object storage for uploaded documentsEU / global edge
AnthropicLLM inference for extraction, compliance and draftingPer provider terms
ResendTransactional email (notifications, approvals)EU / US
StripeSubscription billing and payment processingUS / EU

We will give 30 days' notice before adding a sub-processor that processes tender content.

03 · How the data is handled

The controls that actually exist.

We don't train on your data

Your tenders, requirements and pricing are never used to train models — ours or anyone's. This is a contractual term, not a preference.

Isolation is enforced by the database

PostgreSQL Row-Level Security with FORCE ROW LEVEL SECURITY on every tenant table. The app connects as a non-owner role with no BYPASSRLS, and the tenant is pinned inside each transaction.

Encryption

TLS in transit. Encryption at rest via the managed Postgres and R2 layers. Provider API keys are read from the environment and never written to the application database.

Human-in-the-loop

The AI drafts; a person approves. Every sign-off is recorded, timestamped and attributable — there is no path where a model's output ships unreviewed.

Append-only audit

AI calls, approvals and configuration changes are written to a log that can be read and added to, never quietly rewritten.

Your data leaves when you do

Projects, requirements, approvals and the audit trail export as one file. No exit interview, no support ticket.

Running a security review?

Start with the pre-answered questionnaire — it covers most of what a standard vendor assessment asks, so you can skip a round trip.