Controls in the operating workflow
- Role-based access and permissions for platform users.
- TLS-protected connections for web traffic.
- Company-separated workflows and permissions.
- Accounting documents are processed for the client workflow, not for public model training.
- Operational logs support security, diagnostics and reliability.
- Accounting outputs remain subject to customer review and approval.
Parameters fixed before launch
The order or DPA must specify hosting region, encryption at rest, backups, retention and deletion. These parameters depend on the agreed infrastructure and are not implied by this public overview.
Staff access and subprocessors
Staff access is limited by role and operational need. The current subprocessor list, access conditions and change-notification process are provided on request and documented contractually.
Incidents and audit
Incident notification, investigation support, logging and audit-response formats are agreed in the DPA. SOC 2 or ISO 27001 certification is not claimed here without a current certificate.
Due diligence package
Before onboarding, request the access architecture, storage and deletion parameters, subprocessor list, backup approach, incident-response process and security contact.
Discuss your setup ↗