§ 01
Verified data, not generated text
Every requirement we publish traces to a verified applicability rule, a regulation and an official source. Our engine is deterministic - it matches rules, it doesn't write essays.
Where data is incomplete, we say so. Coverage statuses are published per category, and draft regulations are never presented as settled law.
§ 02
Human verification
Rules and requirements are verified by our research team against official sources before publication, with last-verified dates on everything.
§ 03
What we won't claim
We don't claim to replace legal counsel. We don't publish tariff rates, certifications or deadlines we haven't verified. And we don't present AI-generated content as regulatory fact.
§ 04
Security
Customer data is isolated per organization with database-level row security, so one workspace can never read another's. API keys are stored as hashes and rotate on demand; webhooks are HMAC-signed. There are no shared credentials and no cross-tenant reads.
§ 05
Privacy
We collect only what the product needs: account details, your product and assessment data, and privacy-conscious product analytics (event names and counts, never keystrokes or personal content). We do not sell data. Details are in our privacy policy.
§ 06
Data handling
Your product data stays in your organization workspace. Documents live in private, organization-isolated storage and are served through short-lived signed URLs - never public links. Exports you generate are yours; we don't resell or republish customer data.
§ 07
Infrastructure
The platform runs on managed cloud infrastructure with encrypted connections in transit. Backups are taken by the managed database provider. Secrets (API keys, provider credentials) live in server-only configuration, never in client code.
§ 08
Document security
Uploaded evidence is validated for type and size, stored in a private bucket namespaced per organization, and hashed (SHA-256) so duplicates and tampering are detectable. Document contents are never written to logs, and AI extraction runs server-side only.
§ 09
Access controls
Roles (owner, admin, member, reviewer) gate every action: who can create products, run assessments, manage billing, or publish content. Platform administration is restricted to staff, and every privileged action is written to an append-only audit log.
§ 10
Data retention
We keep operational records (assessments, reports, audit logs) for as long as your workspace needs them, and enterprise plans can configure retention policies per data type (assessments, reports, documents, audit logs, analytics, contact data) with anonymize, delete or archive actions on expiry. Contact-form submissions are kept only to handle your request.
§ 11
Auditability
Every assessment records who ran it, which product data existed, which rules fired, which sources were consulted, and which AI model (if any) was used. Report versions are immutable, so you can always show exactly what you were told and when.
§ 12
AI safeguards
AI is assistive, never authoritative. It may draft summaries and suggest classifications, but it cannot invent legislation, certifications, HS codes, tariff rates or source URLs - guardrails reject outputs that do. AI suggestions are always labeled as suggestions, and regulatory conclusions come only from the deterministic rule engine and verified records.
§ 13
Source provenance
Every public claim links to a source record with a level (official legislation, recognized standard, or secondary reference), a publisher, an official URL, and a last-checked date. Source limitations are shown on source pages, and unverified sources never drive customer-facing conclusions.
§ 14
Compliance methodology
Regulations become structured requirements: extracted from official legal text, encoded as applicability rules, verified by researchers, then published. Changes to regulations trigger re-verification of affected rules and alerts to monitoring subscribers. The full pipeline is described on our methodology page.