OSO Audit

Trust Center

Everything procurement asks for, in one place.

This page collects the evidence an IT, legal or procurement reviewer needs — and states plainly what does not exist yet. A vendor that rounds "planned" up to "done" on its trust page will do it in its audit trail too.

Control summary

Tenant isolation

Dedicated database per firm plus row-level security enforced at the database layer, adversarially tested through an unprivileged role.

Tamper-evident records

Hash-chained audit trail, append-only ledgers for AI actions and sign-off notes, HMAC-bound sign-offs with rotating keys, RFC-3161 trusted timestamps.

Evidence integrity

SHA-256 hashing at ingest, signed evidence-pack exports with a manifest and an offline verifier, PDF/A-3 archival with evidence embedded.

Access

SAML/OIDC SSO, SCIM provisioning, TOTP MFA for privileged roles, engagement-level permissions beneath firm-level roles.

Data protection

Encryption in transit and at rest, field-level encryption for stored credentials, key rotation, file-based secrets management, retention rules with legal-hold suspension.

Resilience

Scripted disaster-recovery drills with point-in-time recovery, nightly backups, and deployment-region options including in-country sovereign routing.

AI governance

Every consequential AI action is recorded append-only with the pinned model version, prompt hash, grounding sources and the human decision that followed — accepted, edited or rejected, with the edit itself captured. Engine runs carry a reproducibility token so a result can be re-run and compared byte-for-byte. High-judgment fields cannot be concluded by a model at all: they are gated to named humans, and sign-off is blocked while any tier-one AI proposal is undispositioned.

Client engagement data is not used to train shared or cross-firm models. Model routing is region-aware, and firms can restrict providers and regions by policy — including in-country options for sovereignty-constrained deployments.

Sub-processors

For this website and our corporate operations:

ProviderPurposeData involved
CloudflareWebsite hosting (Pages) and DNSStandard server logs (IP, timestamp, page, user agent)
Microsoft 365EmailCorrespondence you send us
AnthropicLLM API for product AI featuresEngagement content submitted to AI features, under API terms that exclude training on customer data

The engagement-specific sub-processor schedule — which depends on your deployment model (self-hosted deployments have none of ours) — accompanies the data processing agreement at contracting, with change notice.

Compliance posture — the honest version

ItemStatus today
SOC 2 Type 2Not certified. Planned, with the underlying technical controls already operating. We will claim it when the report exists, not before.
Independent penetration testScope prepared — including LLM-specific attack surface (prompt injection, cross-tenant retrieval, tool authorization). Execution is sequenced ahead of first enterprise deployment.
Data processing agreementProvided with the licence agreement for any engagement involving personal data.
Regional security frameworksWe support customer reviews against frameworks such as SAMA CSF and NCA ECC where your scope requires them — as evidence mapping in your review, not as a certification claim.
Vulnerability reportsWrite to [email protected]. We acknowledge fast and fix in the open with you.

Security review

Send the questionnaire early.

We would rather answer it now and lose fast than discover a blocker at signature.

Send your questionnaire Security & deployment detail