Trust center · Security

Designed closed.
Verified in the open.

Security statements below are separated into what is designed, what is verified by defined tests, and what remains open — status is stated as status.

Architecture posture

Controls live where they cannot be skipped.

The product is designed so that access rules, tenancy boundaries, and record immutability are enforced at the data layer and fail closed — an application bug should deny access rather than grant it.

Encryption

Data encrypted in transit and at rest by design, with organization-scoped keys.

Access

Role- and relationship-scoped access enforced at the database layer.

Auditability

Consequential actions land in an append-only audit design.

Least privilege

Service credentials are confined to narrow, named duties.

Verification practice

Every change walks the same gauntlet.

Changes pass an automated, fail-closed verification chain — tests, boundary checks, dependency audit, and secret scanning — before merge. A change that weakens a control is designed to be rejected by the pipeline, not caught later by hope.

Certification status

No certification theater.

We do not claim a completed SOC 2 or equivalent certification. Current certification, audit, and assessment status is shared directly in diligence, with dates and scope, rather than implied publicly.

This website

The marketing site practices what it states.

This site is static, carries no advertising trackers and no session replay, and runs behind a restrictive content-security policy. One disclosed measurement tool runs: Apollo.io visitor analytics, used to understand organizational interest in a design partnership — see the privacy notice.

Raise a concern

Security reports are welcome.

Report a suspected vulnerability or security concern to privacy@peacefull-ai.io. Do not include PHI. We do not pursue good-faith researchers.