What we enforce, what we attest, and what we do not claim.
Security pages usually list only the good news. This one separates the three categories, because a reviewer needs to know which is which.
1 · What the platform enforces
Capabilities in the shipped product, demonstrable in a live system.
| Control | How it is enforced |
|---|---|
| Tenant isolation | Row-level security in the database, not application-level filtering |
| Role-based access | Role and workspace evaluated on every request |
| Single sign-on | OIDC |
| Multi-factor authentication | MFA challenge at login |
| Directory provisioning | SCIM |
| Action attribution | Every action recorded against the acting user |
| Tenant-scoped audit trail | Actions queryable per tenant |
| Policy, rule and limit governance | Versioned objects, not free text |
| Budget and notification limits | Enforced by the platform |
| Model promotion gate | Refuses on provenance, divergence, null-baseline and unmeasured-horizon checks |
| Override attribution | Human overrides of a gate refusal are logged with actor and reason |
| Edition gating | The demo simulator exists only in the demo edition |
Why tenancy belongs at the database layer. If isolation is enforced in application code, one missed filter (one query, one new endpoint, one refactor) is a cross-tenant leak. Moving the control into the database means the application’s failure mode is closed rather than open. It is the single most important architectural security decision in the product.
2 · Data posture
| Question | Answer |
|---|---|
| What access do you need to our systems? | Read-mostly by default: events and reference data. |
| Can you write into our systems? | Only through explicit, named, audited actions. |
| Is there a background write path? | No. |
| What happens to events that fail to map? | They land in a dead-letter view with the reason. Nothing is silently dropped. |
| Do you become our system of record? | No. Your warehouse stays yours. |
| Can it run in a segmented network? | Yes. The read-mostly posture is why plant and operational-technology deployments are viable. |
| Can another customer’s data reach ours? | No. There is no cross-tenant path of any kind. See cross-domain. |
Answers to what reviewers ask first
| Question | Answer |
|---|---|
| Where does it run? | In infrastructure you control: single-host containers, Kubernetes, or your cloud account with a managed database. See deployment. |
| Where does our data live? | Where you put it. There is no shared hosted estate. |
| How is tenant isolation enforced? | By the database, not the application. An application defect cannot widen visibility. |
| How do users authenticate? | Single sign-on over OIDC, directory provisioning over SCIM, multi-factor authentication at login. |
| What can it write to our systems? | Nothing by default. Any write is a named, audited action. |
| How do events get in? | Streams, REST sources, scheduled pulls or bulk import. Failures are held in a dead-letter view. See event-driven. |
| Can a model reach production unvalidated? | Not by default. The promotion gate refuses and records why. An override is attributed. |
| Is there an audit trail? | Every action is recorded with the acting user, scoped to the tenant. |
| Can another customer’s data reach ours? | No cross-tenant path exists. |
| Where is the security documentation? | We walk reviewers through it in a conversation and answer the questionnaire directly. |
3 · What this page does not claim
This section is the point of the page.
A security reviewer should see the gaps in the same detail as the controls. If a claim is not in section 1, it is not claimed. For each item below, this page makes no statement either way. Ask us, and we will give you the current position in writing.
| Item | Position on this page |
|---|---|
| SOC 2 and ISO 27001 | Not claimed. Ask for current status. |
| Penetration test report | Not claimed. Ask for the most recent date and scope. |
| Data residency options | Deployment is into infrastructure you control. No hosted region list is published. |
| Data processing agreement and sub-processor list | Not published here. Ask for the current documents. |
| Accessibility conformance statement | Not claimed. |
| Regulatory mapping (financial, health, public sector) | Not claimed. We state controls; your compliance function maps them. |
| Whether customer data trains models used by other tenants | No cross-tenant path exists in the platform (section 2). The contractual position is available on request. |
| Model and data ownership terms | A contractual matter. Ask for the current position. |
The audit trail, in the product
Every blocked and held action is recorded with its reason.
Fictional reference world: OgMartPut your security reviewer in the room
Bring the questionnaire. A conversation is faster than a document, and the answer comes with the person who can demonstrate it.