For your review
The pack, before you ask for it.
Most of what a reviewer needs is already published on this site rather than held back for a qualified conversation. This page is the index, plus the parts that are sent directly because they change with dates.
The reasoning is straightforward: a review that starts with a questionnaire and a three-week wait is a review that stalls. If the honest answers are public, the only thing left to discuss is whether they suit you.
Published
Read these without talking to anybody.
| Document | Answers |
|---|---|
| Security model | The isolation rules, how each is enforced, and the four open items we would raise unprompted. |
| Whose permissions apply | Per connected system, whether your person's own permissions are enforced by that system or only by us. Two of four rows are us. |
| Permission gates | The four narrowing checks, and why none of them can widen access. |
| Audit trail | What is recorded, what is deliberately not recorded, who can read and export it. |
| Limits | What is structurally impossible, what is deliberately refused, and what is simply unfinished. |
Sent directly
These carry dates, so they are not left on a web page to go stale.
Certification status
Where we actually are, per framework, with dates – including the parts that would not pass today. A status rather than a badge wall.
Sub-processor list
Who else is involved in running the service, what they do, and where. Short, because the architecture keeps it short.
Data handling and retention
What is held, what is never held, how long the audit trail lasts, and what happens to it when you leave.
Architecture diagram and data flows
Where requests go, which credential is used at each hop, and which components can reach a client database at all.
Questions we expect
The five that come up every time.
Asked
- Do you store our data?
- Can one client reach another's?
- What happens when somebody leaves?
- Can we get process isolation?
- Has this been penetration tested?
Answered
- No figures, no documents. Metadata, grants and audit only.
- Enforced twice – where grants are created and again where they are used.
- Their sign-in stops working, in your directory. Nothing to expire on our side.
- Yes, as a second instance with only your projects reachable. It is a deployment decision, not a redesign.
- Not externally, yet. Internal adversarial reviews have been run and their findings fixed. That is not the same thing and we will not pretend it is.
Ask for the pack.
Say which frameworks matter to you and it comes back with the honest position on each, including the gaps.