Trust · Compliance evidence
What we have today, what's in progress, what's planned.
We list every control honestly. We do not claim certifications we do not hold. Procurement, security and legal teams can use this page as the starting point for a vendor risk assessment.
Data protection
- Security overview
Encryption in transit & at rest
ImplementedTLS 1.2+ on all endpoints. AES-256 at rest on managed Postgres and object storage.
Data residency
- Sub-processors
EU-only hosting & processing
ImplementedPrimary region eu-central. Sub-processors documented with region and data category.
Access control
- Architecture & security
Row-Level Security on tenant data
ImplementedRLS enabled on every tenant-scoped table. Service-role access limited to verified server functions.
- No external evidence yet
Email + Google SSO
ImplementedSessions stored client-side, validated server-side on every privileged request.
Accountability
- Audit export
Governance audit log + CSV export
ImplementedEvery governance decision is captured as an event and exportable to CSV for steering committees.
Data subject rights
- Data controls
Self-serve hard delete
ImplementedCustomers delete documents, findings or extracted concepts from the UI. Hard delete — not soft delete.
Contractual
- Download DPA
GDPR Art. 28 DPA template
ImplementedDownloadable template (v1.0). Counter-signed copy issued by legal within 5 business days for pilots.
Enterprise access
- SSO playbook
SAML 2.0 SSO
In progressAvailable for pilot tenants. Concrete IdP wiring playbook (Okta, Entra ID, Google Workspace) published.
Assurance
- No external evidence yet
Independent penetration test
PlannedFirst external pen-test scheduled before first production tenant go-live. Summary report shared under NDA.
- No external evidence yet
ISO 27001 alignment
In progressControls mapped to ISO 27001 Annex A. Formal certification not yet pursued.
- No external evidence yet
SOC 2 Type II
Not yet initiatedNot yet initiated. Tracked as a post-pilot milestone; will be confirmed publicly when an auditor is engaged.
- No external evidence yet
Vulnerability disclosure
Implementedsecurity@wikisure.org. Triage within 2 business days. Coordinated disclosure preferred.