Current-state trust center
The trust center is a ledger, not a brochure.
Production deploy
ValidatedThe current release passed exact-commit CI, E2E, Lighthouse, security, dependency, build, and Cloud Run deployment gates. API, auth, and web revisions are Ready at 100% traffic.
Evidence: current release packet
Public UI health
ValidatedPublic root, sign-in, unauthenticated redirects, request-access, static trust pages, API readiness, and browser console behavior were tested in production.
Evidence: production browser verification
Authenticated value
Validated with simulated tenantA fixed simulated production tenant exercised authenticated routes, conversation streaming, durable feedback, findings, artifacts, activity proofs, and encrypted attachment upload/download. Real-customer proof and a physical passkey ceremony remain separate evidence lanes.
Boundary: simulated UAT, not customer adoption
Attachment security
ValidatedProduction UAT verified KMS-wrapped encryption, ciphertext-only GCS storage, exact API decryption, structural scanning, retention self-heal, scoped IAM, and canary cleanup.
Evidence: production attachment canary
Compliance claims
Not claimedSOC 2, ISO, HIPAA, GDPR, PCI, DORA, NIS2, external audit, and SLA claims require separate evidence before they can be public claims.
Next: audit artifacts