Authenticated, tenant-segregated access
Organization-scoped records are separated through application authorization and Postgres Row Level Security policies.
ImplementedSecurity, privacy, evidence handling, tenant segregation, package integrity, and procurement documentation presented with implementation status and explicit limitations.
These statements describe implemented product behavior. They are not third-party certifications.
Organization-scoped records are separated through application authorization and Postgres Row Level Security policies.
ImplementedRecorded evidence artifacts include SHA-256 content hashes where the ingestion workflow captures them.
ImplementedRelevant review activity is recorded in append-only audit structures and package-specific examination records.
ImplementedExternal reviewer invitations are bounded to one issued package, time-limited, revocable, and stored using hashed access tokens.
ImplementedPassword recovery uses time-limited Supabase recovery flows and requires a genuine recovery session before password replacement.
ImplementedSome materials are supplied directly so access can be recorded and the current version can be confirmed.
Application records are associated with an organization identifier and subject to tenant-scoped access controls.
Issued packages preserve a manifest hash and bounded package metadata for later verification.
Only human-accepted mappings are presented as affirmative supporting relationships in issued package records.
The Baseline is a point-in-time evidence-readiness assessment. It does not establish continuous effectiveness or monitor the originating AI system runtime.
These capabilities are planned or customer-demand dependent. They are not represented as currently implemented.
Use the company-domain contact for security, privacy, procurement documentation, or evidence-handling questions.