Trust

What we can prove, and what we cannot yet

An ERP holds the most sensitive data a company has, and a young vendor asking for it should be specific about its assurances rather than reassuring. This page states what we have, what is in progress, and what we do not have — the last of which is the part most vendors leave out.

Request the security pack

SOC 2 report, DPA, sub-processor list, penetration test summary, and the correctness suite.

1 / 3
SOC 2 Type I completeType II in progressThird-party ledger review

The six areas

Everything a diligence questionnaire asks about.

Security

Encryption in transit and at rest, MFA, role-based access, audit logging, backups with point-in-time recovery, and managed secrets.

Detail →

Compliance

SOC 2 Type I complete, Type II in progress. GDPR and CCPA handling, DPA available, sub-processors published.

Detail →

Ledger correctness

A published property-based test suite over the accounting invariants, plus a third-party attest review of the engine. Separate from SOC 2, and the one most finance teams actually want.

Detail →

AI data handling

Your data builds your corpus inside your tenant. It is not pooled across customers and not used to train shared models.

Detail →

Error & restatement policy

What happens if we cause a misstatement: detection, notification timeline, correction procedure, and who pays for remediation.

Detail →

Reliability

Uptime targets, incident history, status page, disaster recovery objectives, and how we communicate during an incident.

Detail →

What we do not have

Stating this first, because a trust page that lists only achievements is a marketing page with a padlock on it.

  • SOC 2 Type II is in progress, not complete. Type I attests that controls are designed properly at a point in time. Type II attests that they operated over a period, which is the one that actually matters, and we are in the observation window rather than through it.
  • No ISO 27001. Not started. If your procurement process requires it, we will fail that requirement today and we would rather you know now.
  • No HIPAA BAA. We do not sign them and are not built for protected health information.
  • No FedRAMP. Not applicable to our market and not on the roadmap.
  • US data residency only. All data is held in US regions. If you require EU or UK residency, we cannot serve you today.
  • Short incident history. We are young, so our uptime record covers a shorter period than an incumbent's. That is a genuine information gap for a buyer, not something to spin.
A trust page that lists only what you have achieved tells a diligence team you have not thought carefully about what you have not.

The distinction most vendors blur

SOC 2 assesses whether we run a controlled environment. It says nothing whatsoever about whether the ledger computes correctly. Those are different questions and they need different assurances, and a vendor answering the second by pointing at the first is either confused or hoping you are.

Our answer to the correctness question is threefold: a published property-based test suite over the accounting invariants, written to be readable by an accountant; a third-party attest firm engaged to review the engine and issue a written opinion; and the shadow ledger, which lets you verify against your own books daily rather than taking either of the first two on trust.

What your auditor gets

  • A read-only role with full drill-down from any balance to source documents.
  • Exportable period tie-outs and the variance report from any migration.
  • The complete audit trail — human and agent actions in one schema — exportable in open formats.
  • The authority matrix as configured for your tenant, showing what automation was permitted to do.
  • The published correctness suite and the third-party engine review.

We will also join a call with your auditor without a salesperson present, which sounds minor and is the thing finance teams most often thank us for.

Request the pack

SOC 2 report under NDA, DPA, sub-processor list, penetration test summary, architecture overview, and the correctness suite. Most diligence questionnaires are answerable from it directly.

Questions

What diligence asks.

Is our data used to train models?
No. Your corrections build your own labelled corpus inside your tenant. It is not pooled with other customers and not used to train a shared model. Model providers process your data under agreements that prohibit training on it.
Where is data hosted?
US regions only, with encryption at rest and in transit. If you require EU or UK residency we cannot serve you today, and we will say so rather than proposing a workaround.
What is your RPO and RTO?
Point-in-time recovery with a recovery point objective of five minutes and a recovery time objective of four hours. Both are tested rather than aspirational, and the test results are in the security pack.
What happens if you cause a misstatement?
The error policy sets out detection, a notification timeline, the correction procedure, and who bears remediation cost. It is published rather than negotiated per contract, and we carry technology errors-and-omissions and cyber cover sized to our largest customer exposure.
Can we get the SOC 2 report?
Yes, under NDA. Ask through contact and we will send the pack.
What happens to our data if we leave?
Full export in open formats — ledger, documents, and the complete audit trail — retained for a defined wind-down period. An audit trail that evaporates at contract end satisfies nobody, including us.

Send it to your security reviewer.

The pack answers most questionnaires directly, and we will join a call with your auditor without a salesperson present.