Trust

Security practices

Last updated 17 August 2026

Tenant isolation

Every governance table is protected by row-level security keyed to organisation membership. A request can only read or write rows belonging to an organisation the signed in user is a member of.

Access control

Roles are owner, director, contributor and viewer, stored in a dedicated membership table rather than on user profiles. Narrative approval and publication are restricted to director and owner roles.

Data in transit and at rest

All traffic is served over TLS. The managed database and object storage encrypt data at rest using the platform provider's controls, hosted in the United Kingdom.

AI safeguards

Prompts include only evidence from the requesting tenant. Generated narratives are stored as drafts with citations and cannot be published without a recorded human approval.

Reporting a vulnerability

Please report suspected vulnerabilities to the workspace owner contact configured in Settings, with steps to reproduce. We ask for a reasonable disclosure window before public disclosure and will not pursue good-faith research.

What we do not claim

This page describes implemented practices only. It is not a certification statement: no SOC 2, ISO 27001 or other audit outcome is claimed here.