Trust center

Security claims backed by visible controls.

This page separates protections that are operating now from scale and independent-assurance work that still requires another provider, a second node, or platform eligibility.

Operating controls

Verified in the current production design.

Ready · Encrypted evidence

AES-256-GCM preservation, SHA-256 integrity indexing, no-store staff delivery, and access auditing.

Ready · Private antivirus

ClamAV streams deliberate uploads over an internal-only network and fails closed when unavailable.

Ready · Scoped review integrity

0/0 verified case(s) currently meet high-confidence, evidence-bound enforcement requirements.

Ready · Owner MFA

Owner and staff administration requires authenticator MFA and a current account session.

Ready · Managed persistence

Local WAL and managed database state are reconciled with checksums and sequence validation.

Ready · Recovery drill

Latest isolated restore verification passed at 2026-09-23 15:29Z.

Ready · Signed releases and build provenance

Approved resource manifests and the production build assurance bundle use Ed25519 signatures, public verification material, an SBOM, and a deployable-file inventory.

Ready · Appeals and reversals

Two-person decisions, conflict controls, restricted appeal intake, enforcement logs, and supported rollback are built in.

Scale assurance

Honest limitations and the next proof points.

Next · Independent penetration test

Automated testing and an owner-authorized assessment are not a substitute for an independent third-party report.

Next · Multi-node failover

Production currently has one application node; a second separately hosted node is required for automatic failover.

Next · Native endpoint agent

The web portal scans submitted files and records device posture. Whole-device protection requires a separately code-signed Windows application and platform attestation on mobile.

Next · Discord verification

Discord controls verification eligibility; the application must reach Discord's server threshold before submission.

Report a vulnerability privately.

The machine-readable disclosure file is available at /.well-known/security.txt. Public release assurance is available as a signed provenance record and software bill of materials.