Current-state trust center

The trust center is a ledger, not a brochure.

Status: This page is intentionally conservative. It lists what is currently proven, what is planned, and what remains blocked. It is not an external audit packet.

Production deploy

Validated

The current release passed exact-commit CI, E2E, Lighthouse, security, dependency, build, and Cloud Run deployment gates. API, auth, and web revisions are Ready at 100% traffic.

Evidence: current release packet

Public UI health

Validated

Public root, sign-in, unauthenticated redirects, request-access, static trust pages, API readiness, and browser console behavior were tested in production.

Evidence: production browser verification

Authenticated value

Validated with simulated tenant

A fixed simulated production tenant exercised authenticated routes, conversation streaming, durable feedback, findings, artifacts, activity proofs, and encrypted attachment upload/download. Real-customer proof and a physical passkey ceremony remain separate evidence lanes.

Boundary: simulated UAT, not customer adoption

Attachment security

Validated

Production UAT verified KMS-wrapped encryption, ciphertext-only GCS storage, exact API decryption, structural scanning, retention self-heal, scoped IAM, and canary cleanup.

Evidence: production attachment canary

Compliance claims

Not claimed

SOC 2, ISO, HIPAA, GDPR, PCI, DORA, NIS2, external audit, and SLA claims require separate evidence before they can be public claims.

Next: audit artifacts