Designed to the standards our customers are held to.
We design to SOC 2 and the other frameworks regulated organisations are measured against. We use posture language, never a certification we do not hold.
The standards, and our posture toward each
| Standard | Posture | What that means here |
|---|---|---|
| SOC 2 trust principles | Designed to | Security, availability and confidentiality; pursuing attestation. |
| OWASP and the NIST Cybersecurity Framework | Aligned with | Application security practice and the framework's control families. |
| PIPEDA, Québec Law 25, GDPR | Designed to support | Privacy by design, purpose limitation and the rights people hold over their data. |
| WCAG 2.2 AA and AODA | Built to | Every product surface and this site. |
| Payment card data | Handled by tokenized providers | We never store card numbers. |
| Tamper-evident audit | Every record | An append-only, verifiable history. A product fact, not a standard. |
This page is informational and not legal advice.
Proposed by the system, decided by people
The engine can propose: a classification, a next step, a follow-up. Every proposal shows its sources and how confident it is.
A person approves, edits or rejects, and the record keeps both the proposal and the decision. No timer and no model ever approves anything on its own.
If it has a form, steps, a decider and a clock, it fits.
Proposed by the system, decided by people. Bring the form and the approval chain you have today; we will show it running.