Trust center · Security
Designed closed.
Verified in the open.
Security statements below are separated into what is designed, what is verified by defined tests, and what remains open — status is stated as status.
Architecture posture
Controls live where they cannot be skipped.
The product is designed so that access rules, tenancy boundaries, and record immutability are enforced at the data layer and fail closed — an application bug should deny access rather than grant it.
Encryption
Data encrypted in transit and at rest by design, with organization-scoped keys.
Access
Role- and relationship-scoped access enforced at the database layer.
Auditability
Consequential actions land in an append-only audit design.
Least privilege
Service credentials are confined to narrow, named duties.
Verification practice
Every change walks the same gauntlet.
Changes pass an automated, fail-closed verification chain — tests, boundary checks, dependency audit, and secret scanning — before merge. A change that weakens a control is designed to be rejected by the pipeline, not caught later by hope.
Certification status
No certification theater.
We do not claim a completed SOC 2 or equivalent certification. Current certification, audit, and assessment status is shared directly in diligence, with dates and scope, rather than implied publicly.
This website
The marketing site practices what it states.
This site is static, carries no advertising trackers and no session replay, and runs behind a restrictive content-security policy. One disclosed measurement tool runs: Apollo.io visitor analytics, used to understand organizational interest in a design partnership — see the privacy notice.
Raise a concern
Security reports are welcome.
Report a suspected vulnerability or security concern to privacy@peacefull-ai.io. Do not include PHI. We do not pursue good-faith researchers.