For your review

The pack, before you ask for it.

Most of what a reviewer needs is already published on this site rather than held back for a qualified conversation. This page is the index, plus the parts that are sent directly because they change with dates.

The reasoning is straightforward: a review that starts with a questionnaire and a three-week wait is a review that stalls. If the honest answers are public, the only thing left to discuss is whether they suit you.

Published

Read these without talking to anybody.

DocumentAnswers
Security modelThe isolation rules, how each is enforced, and the four open items we would raise unprompted.
Whose permissions applyPer connected system, whether your person's own permissions are enforced by that system or only by us. Two of four rows are us.
Permission gatesThe four narrowing checks, and why none of them can widen access.
Audit trailWhat is recorded, what is deliberately not recorded, who can read and export it.
LimitsWhat is structurally impossible, what is deliberately refused, and what is simply unfinished.

Sent directly

These carry dates, so they are not left on a web page to go stale.

Certification status

Where we actually are, per framework, with dates – including the parts that would not pass today. A status rather than a badge wall.

Sub-processor list

Who else is involved in running the service, what they do, and where. Short, because the architecture keeps it short.

Data handling and retention

What is held, what is never held, how long the audit trail lasts, and what happens to it when you leave.

Architecture diagram and data flows

Where requests go, which credential is used at each hop, and which components can reach a client database at all.

Questions we expect

The five that come up every time.

Asked

  • Do you store our data?
  • Can one client reach another's?
  • What happens when somebody leaves?
  • Can we get process isolation?
  • Has this been penetration tested?

Answered

  • No figures, no documents. Metadata, grants and audit only.
  • Enforced twice – where grants are created and again where they are used.
  • Their sign-in stops working, in your directory. Nothing to expire on our side.
  • Yes, as a second instance with only your projects reachable. It is a deployment decision, not a redesign.
  • Not externally, yet. Internal adversarial reviews have been run and their findings fixed. That is not the same thing and we will not pretend it is.

Ask for the pack.

Say which frameworks matter to you and it comes back with the honest position on each, including the gaps.