Trust center
What a buyer can verify without sending an email
Every certificate, report and test the organization holds, with its scope, its currency and its exclusions printed next to it; the 14 sub-processors that touch data; 7 months of availability history across 4 components; and a standard 30-question vendor questionnaire answered in place, including the 7 questions the answer to which is that we cannot answer it.
Health
Four readings, each with a printed rule
Nothing here is a judgment. A reading is amber or red because a stated condition is true in the record below it.
Attestation currency
7 of 16
44% current. 2 lapsed, 1 expiring, 3 in progress, 3 not held.
Questionnaire coverage
12 of 30
11 partial, 7 cannot be answered. 18 carry a named evidence reference.
Availability, Jul 2026
99.66%
Weakest component Model gateway at 99.29% against a 99.0% target.
Sub-processor assurance
12 of 14
6 critical, 5 approved with conditions, 2 never assessed.
Operations
The register itself
Scope and exclusions are printed at the same weight as the name of the standard, because a certificate with the wrong scope is worse than no certificate.
Attestations, certifications and tests
16 records · 11 available on request · 14 carry a stated gap
Agentic operations platform: production environment, agent runtime, evidence store and the tenancy boundary.
Covers
Security, Availability and Confidentiality criteria across a nine-month observation window ending 30 September 2025.
Explicitly excludes
The twelve service towers’ upstream source systems, every sub-processor environment, and corporate endpoints.
Processing Integrity and Privacy criteria were not in scope. A buyer asking how agent output accuracy is controlled will not find the answer in this report.
The information security management system covering the agentic operations platform and its operating team.
Covers
Ninety-three Annex A controls, statement of applicability version 4, three-year certificate with annual surveillance.
Explicitly excludes
Corporate IT, employee endpoints and the physical estate.
The year-one surveillance audit is 106 days past the date it should have been scheduled. A certificate stays valid until a body withdraws it, which is not the same as being in good standing.
Agent lifecycle management, the evaluation harness, adversarial testing and the change-release path.
Covers
Stage 1 documentation review completed. Stage 2 audit scheduled for 14 September 2026.
Explicitly excludes
Nothing is certified yet, so nothing is excluded yet.
No certificate exists. Until Stage 2 closes, the estate is running 178 managed agents under a management system nobody outside the team has audited.
Not pursued.
Covers
None.
Explicitly excludes
None.
Privacy commitments rest on the Article 30 record and the signed data processing agreements. Neither is independently certified, and a questionnaire asking for 27701 gets a no.
UK operating entity and the systems it administers.
Covers
Five technical control themes, verified by hands-on testing of a sample of devices.
Explicitly excludes
Non-UK entities.
Lapsed 171 days ago. UK public-sector procurement treats a lapsed certificate as no certificate, so any bid requiring it fails today.
Not pursued.
Covers
None.
Explicitly excludes
None.
No cardholder data reaches any of the twelve towers today. The moment Order-to-Cash accepts a card payment this becomes a gap on day one, and nothing in the platform would flag it.
The cockpit web application, the authentication path, the tenancy boundary and the evidence API.
Covers
Eleven testing days. Two medium and six low findings raised; both mediums remediated and retested on 6 May 2026.
Explicitly excludes
The agent runtime’s tool-calling surface and every model provider API.
The agent runtime was explicitly out of scope. The most novel attack surface in the estate is the one this test did not touch.
Twenty-four attempts across injection, poisoning, exfiltration and tool abuse against the managed agent estate.
Covers
Recorded in full on the adversarial testing page, including the attempts that reached something.
Explicitly excludes
No third party has repeated any of it.
Run by the team that built the agents. It is a useful engineering exercise and it is not independent assurance, and a procurement reviewer is right to score it as the former.
Perimeter, cloud configuration and identity provider integration.
Covers
Superseded by the 2026 H1 test. Retained because the remediation history is part of the record.
Explicitly excludes
Application layer.
Agentic processing of employee data in the Hire-to-Retire tower, the role transition ledger and the works-council packs.
Covers
Necessity and proportionality, the lawful basis for each processing purpose, the rights of the data subject and the residual risk rating.
Explicitly excludes
Customer personal data, which sits under a separate assessment.
Signed by the controller’s own data protection officer. No supervisory authority reviewed it, and none was consulted, because the residual risk was assessed as not high — an assessment made by the same organization that wanted the answer.
Agent decisions affecting customers in the Order-to-Cash tower, including credit hold and dispute outcomes.
Covers
Draft circulated to Legal and Revenue Operations. The Article 22 analysis of solely automated decisions is the open section.
Explicitly excludes
Employee data.
Customer-facing agents are already running at volume while the assessment that should have preceded them is still in draft. That ordering is the finding.
Personal data reaching model providers and infrastructure hosted outside the European Economic Area.
Covers
Onward-transfer analysis for four sub-processors, with supplementary measures listed per destination.
Explicitly excludes
Any provider added after July 2025, of which there are two.
Expires in 40 days and two sub-processors added since it was written are not in it. Renewing it is not scheduled.
The twenty-six surfaces the sensing grid listens on and the balancing test behind each.
Covers
Purpose test, necessity test and balancing test recorded per surface, with the opt-out route named.
Explicitly excludes
Surfaces relying on consent rather than legitimate interest.
Group-wide cover including first-party incident response and third-party liability.
Covers
Twenty-five million dollar aggregate limit, one million dollar retention, incident response retainer included.
Explicitly excludes
Contractual penalties, regulatory fines where uninsurable, and any loss arising from a product recall.
The policy wording predates the agentic deployment. The insurer has not confirmed in writing that an autonomous agent action is a covered act, and nobody has asked.
Not pursued.
Covers
None.
Explicitly excludes
None.
Every evaluation of every agent has been performed by the team that built it. A financial services buyer will ask for independent model validation and there is nothing to send.
Platform continuity: model provider outage, evidence store failure and a full region loss.
Covers
Three scenarios exercised with measured recovery, including the drill that failed and was rerun.
Explicitly excludes
A simultaneous loss of both model providers, which has never been exercised.
Sixteen recovery drills are scheduled and eleven have been run. Eight of those eleven had an independent observer, three did not, and two missed their recovery objective. All of it, including the misses, is on the drills page.
Sub-processors
14 parties · 14 carry personal data · 4 carry special-category data · 2 with no agreement on file
| Party | Category | Processing in | Data | Agreement | Audit right | Assessed | Standing |
|---|---|---|---|---|---|---|---|
Primary model provider Inference for every agent in the estate. Receives prompt content, which includes record extracts. | model-provider | US | Personal | DPA-2025-014 | Report-based. No on-site audit right negotiated. | 41 days ago | Critical Approved with conditions. Zero-retention is contracted and attested annually; it is not independently verifiable by this platform. This is the highest-exposure processor in the register and the one with the weakest audit right. Everything an agent reads passes through it. |
Secondary model provider Failover inference when the primary provider is unavailable or rate-limited. | model-provider | US · IE | Personal | DPA-2025-019 | Report-based, SOC 2 Type II shared annually. | 41 days ago | High Approved. EU region available and used for EEA-origin traffic. |
Applicant tracking vendor Hosts candidate applications, assessment results and interview records. | saas | US · SG | Personal · onward transfer | DPA-2024-006 | Contractual on-site audit right, never exercised. | 3 months ago | High Approved with conditions. The vendor uses two onward processors for resume parsing and video interview hosting. The audit right exists and has never been used. An unexercised audit right is a contract clause, not an assurance. |
Resume parsing service Extracts structured fields from uploaded resumes on behalf of the applicant tracking vendor. | saas | US | Personal | none on file | None. This is an onward processor; the relationship is with the applicant tracking vendor, not with us. | never | High Not assessed. Identified from the vendor sub-processor page during the 2026 review, not from any notification. A processor handling candidate resumes that we have never assessed and have no direct contract with. It was found by reading the vendor website. |
Video interview platform Hosts recorded and live interviews, and stores the recordings. | saas | US · DE | Personal · special category | DPA-2025-021 | Report-based. | 3 months ago | High Approved with conditions. Facial analysis features are contractually disabled; the platform cannot verify they are off. Video recordings are biometric-adjacent. Contractual disablement of facial analysis is asserted by the vendor and not observable from here. |
Customer platform vendor Hosts customer contact records, opportunity and quoting data. | saas | US · DE · SG · AU | Personal | DPA-2023-002 | Report-based, ISO 27001 and SOC 2. | 12 months ago | Critical Approved. Regional instances configured. Sub-processor list refreshed twice since the last assessment. Last assessed 348 days ago against a sub-processor list that has changed twice since. |
Contact center vendor Voice, chat and email handling, plus transcript generation and storage. | saas | US · DE · SG · AU | Personal · special category · onward transfer | DPA-2023-004 | Report-based. | 12 months ago | Critical Approved with conditions. Speech-to-text runs through an onward processor. Transcripts carry whatever the customer says, including health and financial detail. Assessed as ordinary personal data. |
Speech recognition service Converts recorded calls to text for the contact center vendor. | model-provider | US | Personal · special category | none on file | None. Onward processor of the contact center vendor. | never | High Not assessed. Named in the vendor sub-processor list; no direct relationship exists. Every recorded customer call in the estate passes through a processor we have never assessed. |
Core HR vendor Employee master, compensation, performance and payroll processing. | saas | US · NL · SG | Personal | DPA-2024-001 | Contractual audit right plus annual third-party report. | 41 days ago | Critical Approved. EU pod confirmed for German and UK populations. |
Infrastructure provider Hosts the platform, the ledger, the warehouse and the evidence spine. | cloud | US · DE · UK · SG · AU | Personal | DPA-2022-001 | Report-based, full compliance program published. | 41 days ago | Critical Approved. Regions pinned per record class; no cross-region replication configured outside the declared routes. |
Marketing and analytics vendor Campaign automation, digital analytics and attribution. | analytics | US | Personal | DPA-2026-002 | Report-based. | 41 days ago | Medium Approved under the EU-US Data Privacy Framework, certification verified February 2026. |
Shared-service outsourcing partner Human staff in the Singapore hub who handle escalated transactions across all four towers. | bpo | SG · IN | Personal · onward transfer | DPA-2024-008 | On-site audit right, exercised October 2025. | 10 months ago | Critical Approved with conditions. Delivery staff in a second country were disclosed during the on-site audit and are now named here. Delivery from a second country was discovered during audit rather than disclosed in advance. The register now names it; the disclosure failure is not undone by that. |
Background screening vendor Right-to-work verification and criminal record checks where lawful. | saas | UK · US · SG | Personal · special category | DPA-2024-016 | Contractual audit right, exercised March 2026. | 41 days ago | High Approved. Criminal record checks are suppressed in jurisdictions where they are unlawful for the role. |
German payroll bureau Statutory payroll filing and social contribution reporting for the German entity. | payroll | DE | Personal | DPA-2023-011 | On-site audit right, exercised annually by the German entity. | 4 months ago | High Approved. Data stays in Germany throughout. |
Actions
What a person has to do before the next buyer asks
Ordered by how visible the gap is to somebody outside the organization. Nothing on this list closes itself.
Attestations that are out of date
2Cyber Essentials Plus · Infrastructure penetration test
Questions procurement will ask that we cannot answer
72.5 · 2.6 · 3.5 · 4.1 · 4.4 · 6.2 · 7.2
Sub-processors carrying data with no completed assessment
2Resume parsing service · Speech recognition service
Certificates inside the renewal window
3Schrems II / EU standard contractual clauses (40 days) · ISO 22301 aligned (86 days) · AICPA Trust Services Criteria (87 days)
Sub-processors with no signed data processing agreement on file
2Resume parsing service · Speech recognition service
Live observability
Availability, month by month, component by component
48 incidents and 919 minutes of major outage over the window. A cell is amber where the month came in under its own target.
Uptime history
4 components × 7 months · 4 of 28 component-months below target · none of these figures is metered
| Component | Target | Jan 2026 | Feb 2026 | Mar 2026 | Apr 2026 | May 2026 | Jun 2026 | Jul 2026 | Incidents |
|---|---|---|---|---|---|---|---|---|---|
| Cockpit application | 99.9% | 99.94 | 99.94 | 99.97 | 99.8184m | 99.96 | 99.99 | 99.92 | 6 |
| Agent runtime | 99.5% | 99.62 | 99.62 | 99.71 | 98.94271m | 99.55 | 99.68 | 99.4162m | 15 |
| Evidence API | 99.9% | 100.00 | 100.00 | 99.98 | 99.96 | 100.00 | 99.99 | 100.00 | 1 |
| Model gateway | 99.0% | 99.44 | 99.44 | 99.12118m | 98.71340m | 99.38 | 99.51 | 99.2944m | 26 |
Measured by the platform’s own health check from two regions at one-minute intervals. There is no independent monitor.
Is policy and strategy coming to fruition
A standard vendor questionnaire, answered in place
The test for this page is not that it looks complete. It is that a procurement team can work top to bottom through 30 questions across 7 sections and finish without sending an email — including the 7 questions where the honest answer is that we do not hold what is being asked for.
Completed in place
40%
12 answered outright of 30.
Answered with a stated gap
11
The answer goes as far as the record goes and then says where it stops.
Cannot be answered
7
No certificate, no test, no metered data. Saying so is the answer.
Backed by a reference
18 of 30
30 of those open a surface inside this product.
Company and contract
3 questions · 2 answered · 1 partial · 0 cannot answer
The services are contracted through the group operating entity incorporated in Ireland, with local service schedules in the United States, the United Kingdom, Germany, France, Brazil, Singapore and Australia. The entity list and the schedule that applies to each country sits on the residency page.
Ninety days either side. Service continues unchanged for the whole notice period; the estate is frozen rather than degraded, and the exit plan starts on the day notice is received rather than at the next renewal.
Yes to the first, not confirmed on the second. A $25 million cyber liability policy is in force to March 2027. Whether an incorrect decision taken autonomously by an agent falls inside the policy has been raised with the broker and has not been answered in writing. Treat agentic acts as uncovered until it is.
Security
7 questions · 3 answered · 2 partial · 2 cannot answer
Yes. Type II covering security, availability and confidentiality for the twelve months to 31 January 2026, issued by an independent firm. The report is released under non-disclosure on request; the scope, exclusions and opinion are stated on the trust center without one.
The certificate is current to October 2027. The annual surveillance audit was due on 4 May 2026 and has not been held; it is 46 days overdue and rescheduled for 28 July. A certificate stays valid through a late surveillance audit up to a limit, and we are inside that limit, but the honest position is that the certification is current and its supervision is late.
An independent test of the cockpit application and its APIs completed on 12 March 2026. The agent runtime was explicitly out of its scope. A second test covering the runtime, prompt handling and tool invocation is under way, and it is being run by our own red team rather than an independent firm, so it will not carry independent assurance when it reports.
Twenty-four adversarial attempts have been run against the estate across fifteen techniques, producing nineteen findings. Every attempt, what it reached and whether the finding is closed is published on the adversarial page, including the attempts that succeeded.
Not currently. The Cyber Essentials Plus certificate expired on 28 February 2026 and has not been renewed. Recertification is scheduled but not booked. If this is a mandatory requirement of your process we do not meet it today.
No, and it is out of scope. The estate does not store, process or transmit cardholder data at any station. If your process requires a PCI attestation regardless of scope, we cannot provide one.
Identity is federated through a single provider with enforced multi-factor authentication. Agents hold service credentials scoped to the authority granted to them, and 309 authority grants are enumerated with the value ceiling and second-signature rule attached to each. The duties page shows every pair of duties that must not be held together and where the estate currently breaches that.
Privacy and data protection
6 questions · 2 answered · 3 partial · 1 cannot answer
For the hire-to-retire tower, yes — completed and signed on 19 February 2026. For order-to-cash the assessment is still in progress while the agents in that tower are already running in production. That sequence is the wrong way round and it is recorded as such rather than presented as work in flight.
The full sub-processor register is published on the trust center with the purpose, the record classes each one touches, the processing locations, the data processing agreement reference and the last assessment outcome. Thirty days of written notice before any addition, with a right to object.
Processing locations are published per record class on the residency page. Transfers out of the EU rely on standard contractual clauses supported by a transfer impact assessment, and that assessment expires in 40 days. Two sub-processors added since it was written are not covered by it.
No. Every provider endpoint in the registry is contracted with training excluded and zero retention. The self-hosted models never leave our tenancy at all, and special-category personal data is routed only to those. Each entry in the model registry states its data boundary and its training position individually.
No. It has not been pursued and no timetable exists. The privacy programme runs against the data protection regulation directly rather than against a certified management system.
Retention is set per record class and published. Deletion propagates through the operational stores. It does not propagate through the nightly extracts written to our own object storage, which currently have no retention policy configured, so a satisfied request today can leave a copy behind in an export.
AI governance
5 questions · 2 answered · 1 partial · 2 cannot answer
Not yet. ISO/IEC 42001 is at stage 2 audit, booked for 14 September 2026. Until that audit passes there is no independent assurance over the AI management system, and no amount of internal documentation substitutes for it.
Twelve models are registered. Each carries its provider, version, modality, hosting location, data boundary, training position, contract type, the towers and agent count that call it, its lifecycle status and its named substitute. Three are self-hosted open weights, two are retired and kept visible, one is under a published deprecation notice.
Every model has a named substitute except three. Eight of the nine named substitutions have been tested against the golden sets; one has not. The untested one is the embedding model, and replacing it means re-embedding the entire retrieval corpus — work that has never been scoped or costed. One model is under a hard end-of-life date 135 days away with 168 agents still calling it and no named owner for the cutover.
No. Every evaluation in the estate runs against golden sets written by the team that built the agents. A passing suite shows an agent behaves the way we specified; it does not show that the specification is right. No model risk management review has been performed by anybody outside that team.
Agents move through five stages against evidence gates, and demotion is armed automatically when a gate stops holding. The full stage history for every managed agent, including every promotion and every demotion with the evaluation run behind it, is published. 178 agents are under lifecycle management and 1,183 are not, which is stated on the page rather than left to be discovered.
Resilience
3 questions · 2 answered · 1 partial · 0 cannot answer
Six months of monthly availability for four components against their targets, with incident counts and major-outage minutes. It is self-reported from our own monitoring. There is no independent monitor and no third party has verified any of these figures.
The continuity exercise aligned to ISO 22301 ran on 12 May 2026 across three scenarios — model provider outage, evidence store failure and full region loss. Separately, sixteen recovery drills are scheduled and eleven have been run; two of those missed their recovery objective and three had no independent observer. Every drill, including the two misses, is published.
Six of every ten inference dollars go to one model provider. Three of the five workloads with that provider have a tested route to a second provider. The embedding workload does not, and that is the concentration that matters rather than the headline share.
Portability and exit
3 questions · 0 answered · 2 partial · 1 cannot answer
Fourteen asset classes in CSV, JSON, JSONL, Parquet, Markdown and PDF — all open, none proprietary. Four have a live route or a nightly job; ten are produced by hand from a database query. The full extract is planned at fourteen days and that assumes the hand-produced ones go right first time.
Two of fourteen asset classes have been read outside the product — the evidence packs and the trust register, both through live routes an auditor has used. The other twelve have never been imported into anything. No parallel run and no restore verification has ever been performed. This is the weakest point in the exit plan and the plan depends on it.
The run-book is generated from the same tables the product reads, so it cannot go stale, and it has never been handed to anyone outside the team that wrote it. Deletion produces a signed certificate listing every store; backups age out over 35 days rather than being deleted immediately, and the certificate says so.
Sustainability
3 questions · 1 answered · 1 partial · 1 cannot answer
Reported weekly for the estate, for each of the twelve towers and for each of the twelve models, with a five-week trend. It is derived from call volume by arithmetic, not metered. No provider in the registry discloses metered energy per request, so the ranking between towers is meaningful and the absolute kilowatt hours are an estimate.
No. None of the three model providers exposes per-request energy, and the self-hosted models run on shared accelerators where consumption is not attributed per tenant. Anyone claiming a metered per-transaction figure for hosted inference today is estimating it the same way we are and calling it something else.
Eighteen employee and customer measures are published, each paired with the throughput measure it sits beside. Seven of them have moved the wrong way while throughput improved, including the share of customers who reached a person when they asked, which fell from 69 percent to 44.2.
What this page is, and what it is not
A security certification and a penetration test are organizational attestations. The product can house them, track their currency and surface their scope; it cannot manufacture them. Present the trust center as the place they live, never as evidence that they exist.
Concretely: of the 16 records above, 7 are current, 2 have lapsed and 3 are not held at all. The uptime history is drawn from the modeled estate and is not metered by an independent monitor. The sub-processor register lists 14 parties, of which 2 have never been assessed and 2 have no agreement reference on file. None of that is hidden behind a request form, and none of it should be read as an audit.