Trust Center
What buyers should verify — not badges to click through. Nothing here claims assurance we cannot evidence.
Verifiable today
| Claim | How you verify it |
|---|---|
| Source stays local on scan | Run unveilr scan offline; only login / --upload touch the network; findings carry masked tokens, never raw secrets. |
| Deterministic enforcement | Same input ⇒ same findings and hashes. No model in any enforcement path; AI triage is advisory-only. |
| Tamper-evident evidence | Every governance action is hash-chained per tenant; GET /v1/evidence/verify and NDJSON export re-hash independently. |
| Fail-closed defaults | Production refuses to boot with dev auth or default secrets; empty agent scopes allow nothing; deny is the policy default. |
| Bring-your-own agent IdP | Okta / Entra / OIDC JWTs verified against tenant JWKS; unbound or unapproved subjects deny on Gateway and govern/check. See Enterprise agent identity. |
| Self-hostable | Full AWS Terraform in-repo; the platform runs in your VPC — we never need your source or traffic. See Self-hosting. |
| Checksummed releases | Release pipeline ships SHA-256 checksums + SPDX SBOM (build provenance when enabled). |
Also available under NDA: Security packet (DPA, retention, IR, subprocessors, architecture).
SOC 2 — honest status
We are not SOC 2 Type I or Type II attested yet. Do not treat this page as a compliance certificate.
The product already implements many of the technical controls auditors map to Trust Services Criteria (tenant isolation, hashed tokens, SoD on the agent gate, hash-chained evidence, fail-closed boot, release SBOM). The remaining work is organizational: policy adoption, access reviews, vendor DPAs, pen test, and an observation window with a compliance automation vendor (Vanta or Drata).
Recommended sales language until a report exists:
SOC 2 Type I/II not yet attested. Technical controls and the full security packet (architecture, DPA, retention, subprocessors) are available under NDA. Type I is the next milestone after vendor onboarding + pen test.
Path detail for operators: private monorepo docs/SOC2_READINESS.md and
docs/SOC2_ONBOARDING_RUNBOOK.md.
What we deliberately do not claim
- “SOC 2 compliant” without a report
- Runtime Postgres RLS assurance without per-deployment verification
- Install commands that 404 — see Installation for works today vs after GA CDN
- Pen-test completion until a named firm and date exist
Related
- Prove — evidence ledger and compliance packs in product
- Security packet — what to request under NDA
- Self-hosting — run Unveilr in your account