New guide: technology risk basics plus a self-assessmentGet it

Security and trust

Sensitive information, handled within verifiable limits.

The service handles architectures, vulnerabilities and incidents. These are the properties trust is built on; nothing on this page goes beyond what we can demonstrate.

01

Isolation between clients

Each client lives in its own context: record, knowledge and permissions kept separate. Nothing from one client is visible from another.

02

Identity and authorization

Every person and every agent operates with its own identity. Each application validates identity and permissions on its own server; the public website does not authenticate.

03

Least privilege

Access is granted per context and per need. What an agent can do is limited in advance, not corrected afterwards.

04

Credential protection

Credentials do not live in the record or in conversations: they are kept custody apart from the content of the service.

05

Traceability

Every conclusion keeps its sources and every action keeps its author and its moment. The work can be reconstructed.

06

Professional validation

Relevant matters pass through the specialist's judgment before delivery. No sensitive result reaches the client without review.

07

Governance of suppliers and models

The suppliers and models behind the service are chosen and reviewed with the same criterion we audit by: evidence.

08

Response to errors

When something fails, it fails closed: access is limited, what is affected is communicated, and it is fixed before reopening.