Skip to content

Trust

Security

These are the MVP controls we run today. Formal certifications ship only with an enterprise deal. We do not invent SOC 2 or ISO badges here.

MVP controls

Tenant isolation
Every tenant-owned row carries organization_id. Client roles never cross tenants.
Auth & access
JWT sessions, membership roles, platform staff scoped to ops endpoints.
Webhook integrity
HMAC signatures and timestamp skew checks on inbound lead webhooks.
Decision audit
Qualification stores policy version, inputs, score contributions, result, and overrides.
Transport & secrets
TLS in transit; production secrets via secret manager-not env dumps in logs.
PII discipline
Operational logs aim to mask phone/email; retention configurable per deployment.

Not yet / not claimed

We do not claim SOC 2 or ISO 27001. Those certifications are scoped with enterprise contracts, not listed as if they already exist.