Trust
Security practices
Last updated 17 August 2026
Tenant isolation
Every governance table is protected by row-level security keyed to organisation membership. A request can only read or write rows belonging to an organisation the signed in user is a member of.
Access control
Roles are owner, director, contributor and viewer, stored in a dedicated membership table rather than on user profiles. Narrative approval and publication are restricted to director and owner roles.
Data in transit and at rest
All traffic is served over TLS. The managed database and object storage encrypt data at rest using the platform provider's controls, hosted in the United Kingdom.
AI safeguards
Prompts include only evidence from the requesting tenant. Generated narratives are stored as drafts with citations and cannot be published without a recorded human approval.
Reporting a vulnerability
Please report suspected vulnerabilities to the workspace owner contact configured in Settings, with steps to reproduce. We ask for a reasonable disclosure window before public disclosure and will not pursue good-faith research.
What we do not claim
This page describes implemented practices only. It is not a certification statement: no SOC 2, ISO 27001 or other audit outcome is claimed here.