Trust & data handling
Your data, on dedicated infrastructure. Access on a ticket, not a whim.
Handing over real operating data is the hard part of any engagement. Here is exactly how it is held, who can reach it, and what we will not claim.
Request an Operational X-Ray01 The controls
What is actually in place.
Described plainly. Only controls that exist — anything not yet built is named as planned, not dressed up as done.
- Dedicated infrastructure
- Your data lands on infrastructure dedicated to your engagement, with per-tenant database isolation. Not a shared pool with other clients’ rows.
- Access on a ticket
- A human operator reaches your data only through a ticket, on scoped credentials, with an audit trail. No standing access, no browsing on a whim.
- Source-backed findings
- Every finding traces to the exact export, rows, and time range that produced it. The current loop is deterministic — no evidence-free findings.
- Coverage honesty
- The system states what it cannot see. Blind spots are named, not buried; the Coverage Map shows what is covered and what is not.
- No data pooling
- We never use one client’s data to answer another’s questions. What compounds across engagements is calibration — how we look — not your data.
“Per-tenant database isolation”1 is the precise claim — your data in its own database, reached on scoped credentials. It is not “physical isolation,” and we will not call it that.
02 What we put in writing
No certification we don’t hold. No exceptions.
We do not publish a certification we do not hold, and we will not imply one. What we will do is put the specifics — encryption in transit and at rest, retention, and deletion — in writing for your engagement, before any data changes hands.
If a control is not in place yet, it is named as planned, not shown as done. The same coverage honesty the findings carry, applied to our own posture. The proof standard is where the evidence discipline lives, and what we don’t claim is said plainly, in public.
03 Questions
The ones a careful buyer asks.
- Where does my data live?
- On infrastructure dedicated to your engagement, with per-tenant database isolation — your data in its own database, not a shared pool.
- Who can access it, and how?
- A human operator, only through a ticket, on scoped credentials, with an audit trail. There is no standing access and no browsing.
- Do you train on or share my data across clients?
- No. One client’s data is never used to answer another’s questions. What compounds across engagements is calibration — how we look — not your data.
- Can I have my data deleted?
- Yes. The engagement is a data slice you send us; your exports and the data derived from them are deleted on request. The specifics go in your engagement agreement.
- Is it encrypted in transit and at rest?
- In transit, yes — every surface of ours is HTTPS-only, so your data reaches us over TLS, and the credentials that run the system are stored encrypted. At rest, the specifics — what is encrypted, what is retained, and how deletion works — are confirmed in writing for your engagement before any data changes hands. We state what is in place and name anything planned; we do not imply a control we do not have.
One way in
See it work on a bounded slice first.
The Operational X-Ray is a fixed-scope look at a data slice you choose — the low-risk way to see how findings, evidence, and coverage are handled before anything bigger.
Request an Operational X-RayWant the method behind the findings? Read how it works.