Start with implemented prototype controls, audit evidence, proof-link handling,
retention tooling, and evidence-pack source material.
2. Separate limits from blockers
DPA limit: no signed DPA or completed DPIA. Security limit: no Cyber Essentials
certificate. Source-evidence limit: packs depend on customer-provided records.
3. Assign buyer owners
Legal/DPO, security, and operations owners should confirm the open decisions
before any production rollout or statutory-clock reliance.
Controlled pilot next step
The trust centre routes to the same controlled-pilot request journey: review the
synthetic demo, check procurement and trust material, then request scoped pilot
planning through the demo-request path.
Pilot scoping is a review workflow only. It does not approve procurement,
production processing, legal compliance, security certification, or live
tenant-data use.
Current Status
DPA/DPIA
Technical annex exists; formal DPA and DPIA approval are not complete.
Cyber Essentials
EvidenceTrail is not yet Cyber Essentials certified.
Subprocessors
No production subprocessors have been appointed.
Auth and sessions
Named operator magic-link sessions exist in code; shared API-key operation
remains available as a controlled fallback where configured.
Database role split
Admin/app database URL separation is implemented for review; production
environment flips still require owner-controlled deployment credentials.
Email delivery
Production Resend delivery is not yet wired; proof-link and digest delivery
remain development/fallback posture until delivery credentials are approved.
Current Assurance Facts
This snapshot reflects current prototype evidence for buyer review. It is not
production security approval, not a completed security questionnaire, and not
legal advice.
Dependency audit freshness
Dependency audit freshness is not current; do not present dependency security as procurement-ready until the audit command records a passing state in an isolated environment.
Prototype restore probe
The SQLite restore probe covers cases, audit events, inbound email metadata,
uploaded attachment metadata, case redactions, and attachment redactions. It
remains prototype restore evidence, not production restore-test evidence.
Statutory source monitor
No statutory source poll artifact is recorded. Run the monitor before relying on legal-risk wording. Copy freeze: active.
No current source-delta evidence is recorded; freeze public legal-risk claim updates until the statutory source monitor passes.
Security response headers
FastAPI middleware applies Content-Security-Policy, Permissions-Policy,
Referrer-Policy, Strict-Transport-Security, X-Content-Type-Options, and
X-Frame-Options to public, operator, and error responses. Buyers still need
deployed-environment header evidence before production approval.
Buyer questions this page answers
Can we use this for a controlled pilot review now?
Yes, for design-partner evaluation or a controlled pilot using agreed data
boundaries; not for broad production rollout or live statutory-clock reliance.
What controls are implemented today?
Current code supports role-bound operator keys, organisation allowlisting,
single-use proof links, manual retention preview and deletion runs, JSON audit
export, redaction stale-source checks, and prototype restore-probe evidence.
What remains a blocker before production?
production SSO, MFA, SCIM, password policy, and persistent user directory;
monitored security contact and approved incident rota; encrypted production
storage and backups; customer-approved DPA/DPIA; certification evidence; and a
signed or immutable evidence bundle.
Outreach promise cross-check
Current outbound sequences and the pilot proposal route reviewers to
/demo, /sample-evidence-pack,
/demo-requests,
/procurement-pack,
/security-questionnaire, and
/pricing. The protected founder proposal template lives at
/operator/pilot-proposal. The public position is conservative: sample data only
for cold outreach, no tenant data in outreach attachments, and EvidenceTrail does
does not guarantee legal compliance, complaint, enforcement, litigation, or cost
outcomes.
Prototype Controls
Operator endpoints fail closed when a data store is configured without credentials.
API keys can be role-bound with organisation allowlisting for prototype operation.
Proof-link submissions are HMAC-signed, expiry-checked, and single-use when
persisted.
Retention controls expose manual retention preview and deletion runs with audit
events for eligible inactive cases.
JSON audit export is available to auditor/admin roles for organisation-scoped
review windows.
Redactions use source-hash stale checks and audit events that avoid original
raw values.
Evidence packs include statutory citations, source registers, custody steps,
source hashes where available, and pack hashes.
Production Launch Gates
Customer-approved Article 28 processor terms and DPIA support pack.
Approved subprocessor schedule and data-residency evidence.
Cyber Essentials or buyer-approved equivalent evidence.
NCSC Cloud Security Principles mapping.
Production identity, MFA, key management, encrypted storage, backups, restore
tests, and incident-response evidence.
Incident Response
Security incident-response draft exists at
docs/security-incident-response-draft.md. It is not a live breach-notification SLA,
and no security contact, tabletop evidence, or production incident rota has
been approved.
Security contact and incident-intake draft exists at
docs/security-contact-intake-draft.md. It is a placeholder only, not a live
monitored security contact, and not a vulnerability disclosure programme.
Backup and Restore
Backup and restore draft exists at docs/backup-restore-dr-draft.md.
Prototype restore evidence exists at
docs/backup-restore-probe-2026-06-10/restore_probe_result.json.
It is not restore-test evidence for production.
No approved production backup system, customer RPO, or customer RTO exists yet.