1. Triage the pack
Confirm whether current evidence is enough for controlled pilot procurement, not production approval.
The buyer room in one page: current evidence, named blockers, owner decisions, sample pack, trust posture, pricing, and pilot request path.
Phase 2 announced for Oct 2026: see what changes.
Confirm whether current evidence is enough for controlled pilot procurement, not production approval.
Route DPA/DPIA, security, and operations blockers to named buyer owners before rollout planning.
Use the demo only after the review team knows which blockers, data boundaries, and pilot questions need testing.
This is not production security evidence, not a signed Data Processing Agreement, and not Cyber Essentials certified. It is a structured index of current prototype evidence and known launch blockers.
The trust centre, security questionnaire, DPA/DPIA notes, and procurement pack describe current posture and launch blockers. Buyer policy should confirm whether current controls satisfy pilot requirements.
Current auth posture includes named operator magic-link sessions in code plus controlled API-key operation where configured. The database role split supports separate admin and app connection URLs, with production credential flips still owner-controlled. Production Resend email delivery is not yet wired, so proof-link and digest delivery claims remain development/fallback until buyer-approved credentials and operational monitoring exist.
Suitable for controlled pilot procurement review, not production procurement approval. The pack is a review-room index for current evidence, named buyer owners, and production blockers.
It carries the UK social-landlord buyer scope while limiting Awaab's Law legal-scope wording to the England social rented sector.
Security questionnaire material is suitable for controlled pilot security review, not production security approval. The DPA/DPIA material is a technical annex for customer legal and DPO review, not a signed DPA.
Security caveat: security headers are applied by the app and role-bound operator access is documented for controlled review, but this is not production security approval, not Cyber Essentials certification, not a pen test, and not evidence of buyer-approved SSO/MFA/SCIM.
Restore caveat: the SQLite prototype restore probe covers case records, audit events, inbound email metadata, uploaded attachment metadata, case redactions, and attachment redactions. It remains prototype restore evidence, not production restore-test evidence, DR SLA evidence, or customer-approved RPO/RTO.
Data caveat: the DPA/DPIA material is a technical annex for customer legal and DPO review. It is not a signed DPA, completed DPIA, approved retention schedule, lawful-basis decision, privacy notice, or transfer assessment.
Dependency caveat: Dependency audit freshness is not current; do not present dependency security as procurement-ready until the audit command records a passing state in an isolated environment.
| Owner | Open decision | Current evidence |
|---|---|---|
| customer legal/DPO owner | confirm Article 28 terms, DPIA, lawful basis, privacy information, retention and deletion/return instructions, and transfer assessment. | docs/dpa-dpia-technical-annex.md and /data-processing-and-cookies. |
| security owner | confirm security questionnaire, Cyber Essentials path, NCSC mapping, vulnerability management, identity controls, and audit evidence. | docs/security-questionnaire-readiness.md and /trust-centre. |
| operations owner | confirm incident rota, monitored security contact, backup/restore evidence, restore-test evidence, and support escalation path. | docs/security-contact-intake-draft.md, docs/security-incident-response-draft.md, and docs/backup-restore-dr-draft.md. |
| Artifact | Path | Current status | Not yet evidence of |
|---|---|---|---|
| Security Questionnaire Readiness | docs/security-questionnaire-readiness.md | Structured buyer-questionnaire answers with evidence links and gaps. | Completed security questionnaire, signed DPA, certification, or pen test. |
| Security Procurement Baseline | docs/security-procurement-baseline.md | Prototype access-control and tenant-isolation evidence. | Production SSO, MFA, pen test, immutable audit log, or signed bundle. |
| DPA DPIA Technical Annex | docs/dpa-dpia-technical-annex.md | Technical input for customer legal and privacy review. | Signed Article 28 terms, completed DPIA, or legal-approved DPA. |
| Dependency Security Checks | docs/dependency-security-checks.md | Dependency audit freshness is not current; do not present dependency security as procurement-ready until the audit command records a passing state in an isolated environment. | Isolated build audit, vulnerability scan, lockfile, or CI security gate. |
| Security Incident Response Draft | docs/security-incident-response-draft.md | Draft intake, triage, breach-assessment, and preservation workflow. | Live security contact, breach-notification SLA, or tabletop evidence. |
| Security Contact Intake Draft | docs/security-contact-intake-draft.md | Draft contact placeholder, vulnerability-disclosure, and incident metadata. | Live monitored contact, security.txt, vulnerability programme, or SLA. |
| Backup Restore DR Draft | docs/backup-restore-dr-draft.md | Draft RPO/RTO, restore-test, and backup evidence requirements. | Approved production backup system, restore-test evidence, or DR SLA. |
| Trust Centre | docs/trust-centre.md | Procurement posture, official references, and launch gates. | Certification, approved subprocessors, backup/DR evidence, or incident SLA. |
| Sample Evidence Pack | /sample-evidence-pack | Downloadable sample-data pack for outreach and buyer review. | Customer evidence, production tenant data, or legal-outcome assurance. |
| Live Read-only Demo | /demo and /awaab-law-demo | Read-only walkthrough using synthetic sample data. | Production environment, customer data, or statutory-clock reliance. |
| Pilot Proposal Statement of Work | /operator/pilot-proposal and docs/pilot-proposal-statement-of-work-2026-06-10.html | Founder-controlled proposal template for human review before sending. | Self-serve checkout, signed order form, buyer acceptance, or promised result. |
| Demo Attachment Assets | docs/demo-assets-2026-06-10/README.md | Outreach screenshots, one-pager, and walkthrough notes. | Customer tenant records, legal advice, or certified security evidence. |
The outreach sequences, one-page summary, and pilot proposal point to the same trust surfaces: /demo, /sample-evidence-pack, /demo-requests, /procurement-pack, /trust-centre, /security-questionnaire, and /pricing. The protected proposal template remains at /operator/pilot-proposal for founder review before any commercial send.
Claims are intentionally bounded: controlled pilot review, sample-data evidence packs, no cold-outreach tenant data, no signed DPA or Cyber Essentials certificate yet, and EvidenceTrail does not guarantee legal compliance, complaint, enforcement, litigation, or cost outcomes.