EvidenceTrail Trust file

EvidenceTrail Trust Centre

Procurement-facing trust posture for early UK-based social landlords. Awaab's Law legal-scope wording is limited to the England social rented sector.

This is not legal advice, not a signed Data Processing Agreement, and not a completed security certification pack.

Phase 2 update

Phase 2 announced for Oct 2026: see what changes.

Buyer review route

1. Check what exists today

Start with implemented prototype controls, audit evidence, proof-link handling, retention tooling, and evidence-pack source material.

2. Separate limits from blockers

DPA limit: no signed DPA or completed DPIA. Security limit: no Cyber Essentials certificate. Source-evidence limit: packs depend on customer-provided records.

3. Assign buyer owners

Legal/DPO, security, and operations owners should confirm the open decisions before any production rollout or statutory-clock reliance.

Controlled pilot next step

The trust centre routes to the same controlled-pilot request journey: review the synthetic demo, check procurement and trust material, then request scoped pilot planning through the demo-request path.

Pilot scoping is a review workflow only. It does not approve procurement, production processing, legal compliance, security certification, or live tenant-data use.

Current Status

DPA/DPIA
Technical annex exists; formal DPA and DPIA approval are not complete.
Cyber Essentials
EvidenceTrail is not yet Cyber Essentials certified.
Subprocessors
No production subprocessors have been appointed.
Auth and sessions
Named operator magic-link sessions exist in code; shared API-key operation remains available as a controlled fallback where configured.
Database role split
Admin/app database URL separation is implemented for review; production environment flips still require owner-controlled deployment credentials.
Email delivery
Production Resend delivery is not yet wired; proof-link and digest delivery remain development/fallback posture until delivery credentials are approved.

Current Assurance Facts

This snapshot reflects current prototype evidence for buyer review. It is not production security approval, not a completed security questionnaire, and not legal advice.

Dependency audit freshness Dependency audit freshness is not current; do not present dependency security as procurement-ready until the audit command records a passing state in an isolated environment.
Prototype restore probe The SQLite restore probe covers cases, audit events, inbound email metadata, uploaded attachment metadata, case redactions, and attachment redactions. It remains prototype restore evidence, not production restore-test evidence.
Statutory source monitor No statutory source poll artifact is recorded. Run the monitor before relying on legal-risk wording. Copy freeze: active. No current source-delta evidence is recorded; freeze public legal-risk claim updates until the statutory source monitor passes.
Security response headers FastAPI middleware applies Content-Security-Policy, Permissions-Policy, Referrer-Policy, Strict-Transport-Security, X-Content-Type-Options, and X-Frame-Options to public, operator, and error responses. Buyers still need deployed-environment header evidence before production approval.

Buyer questions this page answers

Can we use this for a controlled pilot review now?

Yes, for design-partner evaluation or a controlled pilot using agreed data boundaries; not for broad production rollout or live statutory-clock reliance.

What controls are implemented today?

Current code supports role-bound operator keys, organisation allowlisting, single-use proof links, manual retention preview and deletion runs, JSON audit export, redaction stale-source checks, and prototype restore-probe evidence.

What remains a blocker before production?

production SSO, MFA, SCIM, password policy, and persistent user directory; monitored security contact and approved incident rota; encrypted production storage and backups; customer-approved DPA/DPIA; certification evidence; and a signed or immutable evidence bundle.

Outreach promise cross-check

Current outbound sequences and the pilot proposal route reviewers to /demo, /sample-evidence-pack, /demo-requests, /procurement-pack, /security-questionnaire, and /pricing. The protected founder proposal template lives at /operator/pilot-proposal. The public position is conservative: sample data only for cold outreach, no tenant data in outreach attachments, and EvidenceTrail does does not guarantee legal compliance, complaint, enforcement, litigation, or cost outcomes.

Prototype Controls

Production Launch Gates

Incident Response

Security incident-response draft exists at docs/security-incident-response-draft.md. It is not a live breach-notification SLA, and no security contact, tabletop evidence, or production incident rota has been approved.

Security contact and incident-intake draft exists at docs/security-contact-intake-draft.md. It is a placeholder only, not a live monitored security contact, and not a vulnerability disclosure programme.

Backup and Restore

Backup and restore draft exists at docs/backup-restore-dr-draft.md. Prototype restore evidence exists at docs/backup-restore-probe-2026-06-10/restore_probe_result.json. It is not restore-test evidence for production. No approved production backup system, customer RPO, or customer RTO exists yet.

Official References