EvidenceTrail Trust file

EvidenceTrail procurement pack

The buyer room in one page: current evidence, named blockers, owner decisions, sample pack, trust posture, pricing, and pilot request path.

Controlled pilot next step

The procurement pack routes to the same controlled-pilot request journey: review the synthetic demo, check procurement and trust material, then request scoped pilot planning through the demo-request path.

Pilot scoping is a review workflow only. It does not approve procurement, production processing, legal compliance, security certification, or live tenant-data use.

Phase 2 update

Phase 2 announced for Oct 2026: see what changes.

From review to pilot decision

1. Triage the pack

Confirm whether current evidence is enough for controlled pilot procurement, not production approval.

2. Assign owner decisions

Route DPA/DPIA, security, and operations blockers to named buyer owners before rollout planning.

3. Request the walkthrough

Use the demo only after the review team knows which blockers, data boundaries, and pilot questions need testing.

Pilot procurement evidence

This is not production security evidence, not a signed Data Processing Agreement, and not Cyber Essentials certified. It is a structured index of current prototype evidence and known launch blockers.

The trust centre, security questionnaire, DPA/DPIA notes, and procurement pack describe current posture and launch blockers. Buyer policy should confirm whether current controls satisfy pilot requirements.

Current auth posture includes named operator magic-link sessions in code plus controlled API-key operation where configured. The database role split supports separate admin and app connection URLs, with production credential flips still owner-controlled. Production Resend email delivery is not yet wired, so proof-link and digest delivery claims remain development/fallback until buyer-approved credentials and operational monitoring exist.

Buyer decision summary

Suitable for controlled pilot procurement review, not production procurement approval. The pack is a review-room index for current evidence, named buyer owners, and production blockers.

It carries the UK social-landlord buyer scope while limiting Awaab's Law legal-scope wording to the England social rented sector.

Security questionnaire material is suitable for controlled pilot security review, not production security approval. The DPA/DPIA material is a technical annex for customer legal and DPO review, not a signed DPA.

Current assurance caveats

Security caveat: security headers are applied by the app and role-bound operator access is documented for controlled review, but this is not production security approval, not Cyber Essentials certification, not a pen test, and not evidence of buyer-approved SSO/MFA/SCIM.

Restore caveat: the SQLite prototype restore probe covers case records, audit events, inbound email metadata, uploaded attachment metadata, case redactions, and attachment redactions. It remains prototype restore evidence, not production restore-test evidence, DR SLA evidence, or customer-approved RPO/RTO.

Data caveat: the DPA/DPIA material is a technical annex for customer legal and DPO review. It is not a signed DPA, completed DPIA, approved retention schedule, lawful-basis decision, privacy notice, or transfer assessment.

Dependency caveat: Dependency audit freshness is not current; do not present dependency security as procurement-ready until the audit command records a passing state in an isolated environment.

Review owners and open decisions

Owner worklist before production approval
Owner Open decision Current evidence
customer legal/DPO owner confirm Article 28 terms, DPIA, lawful basis, privacy information, retention and deletion/return instructions, and transfer assessment. docs/dpa-dpia-technical-annex.md and /data-processing-and-cookies.
security owner confirm security questionnaire, Cyber Essentials path, NCSC mapping, vulnerability management, identity controls, and audit evidence. docs/security-questionnaire-readiness.md and /trust-centre.
operations owner confirm incident rota, monitored security contact, backup/restore evidence, restore-test evidence, and support escalation path. docs/security-contact-intake-draft.md, docs/security-incident-response-draft.md, and docs/backup-restore-dr-draft.md.

Artifact index

Current procurement artifacts and readiness status
Artifact Path Current status Not yet evidence of
Security Questionnaire Readiness docs/security-questionnaire-readiness.md Structured buyer-questionnaire answers with evidence links and gaps. Completed security questionnaire, signed DPA, certification, or pen test.
Security Procurement Baseline docs/security-procurement-baseline.md Prototype access-control and tenant-isolation evidence. Production SSO, MFA, pen test, immutable audit log, or signed bundle.
DPA DPIA Technical Annex docs/dpa-dpia-technical-annex.md Technical input for customer legal and privacy review. Signed Article 28 terms, completed DPIA, or legal-approved DPA.
Dependency Security Checks docs/dependency-security-checks.md Dependency audit freshness is not current; do not present dependency security as procurement-ready until the audit command records a passing state in an isolated environment. Isolated build audit, vulnerability scan, lockfile, or CI security gate.
Security Incident Response Draft docs/security-incident-response-draft.md Draft intake, triage, breach-assessment, and preservation workflow. Live security contact, breach-notification SLA, or tabletop evidence.
Security Contact Intake Draft docs/security-contact-intake-draft.md Draft contact placeholder, vulnerability-disclosure, and incident metadata. Live monitored contact, security.txt, vulnerability programme, or SLA.
Backup Restore DR Draft docs/backup-restore-dr-draft.md Draft RPO/RTO, restore-test, and backup evidence requirements. Approved production backup system, restore-test evidence, or DR SLA.
Trust Centre docs/trust-centre.md Procurement posture, official references, and launch gates. Certification, approved subprocessors, backup/DR evidence, or incident SLA.
Sample Evidence Pack /sample-evidence-pack Downloadable sample-data pack for outreach and buyer review. Customer evidence, production tenant data, or legal-outcome assurance.
Live Read-only Demo /demo and /awaab-law-demo Read-only walkthrough using synthetic sample data. Production environment, customer data, or statutory-clock reliance.
Pilot Proposal Statement of Work /operator/pilot-proposal and docs/pilot-proposal-statement-of-work-2026-06-10.html Founder-controlled proposal template for human review before sending. Self-serve checkout, signed order form, buyer acceptance, or promised result.
Demo Attachment Assets docs/demo-assets-2026-06-10/README.md Outreach screenshots, one-pager, and walkthrough notes. Customer tenant records, legal advice, or certified security evidence.

Outbound and proposal claim parity

The outreach sequences, one-page summary, and pilot proposal point to the same trust surfaces: /demo, /sample-evidence-pack, /demo-requests, /procurement-pack, /trust-centre, /security-questionnaire, and /pricing. The protected proposal template remains at /operator/pilot-proposal for founder review before any commercial send.

Claims are intentionally bounded: controlled pilot review, sample-data evidence packs, no cold-outreach tenant data, no signed DPA or Cyber Essentials certificate yet, and EvidenceTrail does not guarantee legal compliance, complaint, enforcement, litigation, or cost outcomes.

Next evidence required before production