Trust · Compliance evidence

What we have today, what's in progress, what's planned.

We list every control honestly. We do not claim certifications we do not hold. Procurement, security and legal teams can use this page as the starting point for a vendor risk assessment.

Data protection

  • Encryption in transit & at rest

    Implemented

    TLS 1.2+ on all endpoints. AES-256 at rest on managed Postgres and object storage.

    Security overview

Data residency

  • EU-only hosting & processing

    Implemented

    Primary region eu-central. Sub-processors documented with region and data category.

    Sub-processors

Access control

  • Row-Level Security on tenant data

    Implemented

    RLS enabled on every tenant-scoped table. Service-role access limited to verified server functions.

    Architecture & security
  • Email + Google SSO

    Implemented

    Sessions stored client-side, validated server-side on every privileged request.

    No external evidence yet

Accountability

  • Governance audit log + CSV export

    Implemented

    Every governance decision is captured as an event and exportable to CSV for steering committees.

    Audit export

Data subject rights

  • Self-serve hard delete

    Implemented

    Customers delete documents, findings or extracted concepts from the UI. Hard delete — not soft delete.

    Data controls

Contractual

  • GDPR Art. 28 DPA template

    Implemented

    Downloadable template (v1.0). Counter-signed copy issued by legal within 5 business days for pilots.

    Download DPA

Enterprise access

  • SAML 2.0 SSO

    In progress

    Available for pilot tenants. Concrete IdP wiring playbook (Okta, Entra ID, Google Workspace) published.

    SSO playbook

Assurance

  • Independent penetration test

    Planned

    First external pen-test scheduled before first production tenant go-live. Summary report shared under NDA.

    No external evidence yet
  • ISO 27001 alignment

    In progress

    Controls mapped to ISO 27001 Annex A. Formal certification not yet pursued.

    No external evidence yet
  • SOC 2 Type II

    Not yet initiated

    Not yet initiated. Tracked as a post-pilot milestone; will be confirmed publicly when an auditor is engaged.

    No external evidence yet
  • Vulnerability disclosure

    Implemented

    security@wikisure.org. Triage within 2 business days. Coordinated disclosure preferred.

    No external evidence yet

Need this in a vendor questionnaire? Email security@wikisure.org for the latest evidence pack (DPA, sub-processor list, architecture summary, pen-test plan).

WikiSure™ is designed for secure semantic governance. Your documents remain private, encrypted and under your control. Security & Trust →
WikiSure™ Insurance | Early Access