LensReading which lens this session carries.

Trust center

What a buyer can verify without sending an email

Every certificate, report and test the organization holds, with its scope, its currency and its exclusions printed next to it; the 14 sub-processors that touch data; 7 months of availability history across 4 components; and a standard 30-question vendor questionnaire answered in place, including the 7 questions the answer to which is that we cannot answer it.

Self-serve for procurement

Health

Four readings, each with a printed rule

Nothing here is a judgment. A reading is amber or red because a stated condition is true in the record below it.

Attestation currency

7 of 16

44% current. 2 lapsed, 1 expiring, 3 in progress, 3 not held.

Questionnaire coverage

12 of 30

11 partial, 7 cannot be answered. 18 carry a named evidence reference.

Availability, Jul 2026

99.66%

Weakest component Model gateway at 99.29% against a 99.0% target.

Sub-processor assurance

12 of 14

6 critical, 5 approved with conditions, 2 never assessed.

Operations

The register itself

Scope and exclusions are printed at the same weight as the name of the standard, because a certificate with the wrong scope is worse than no certificate.

Attestations, certifications and tests

16 records · 11 available on request · 14 carry a stated gap

AICPA Trust Services CriteriaSOC 2 Type IICurrentCertificationExpires Nov 13, 2026

Agentic operations platform: production environment, agent runtime, evidence store and the tenancy boundary.

Covers

Security, Availability and Confidentiality criteria across a nine-month observation window ending 30 September 2025.

Explicitly excludes

The twelve service towers’ upstream source systems, every sub-processor environment, and corporate endpoints.

Issuer Acme Global — Chief Information Security Officer· Auditor Marsden Wright LLP· EV-TRUST-SOC2-01· Available on request

Processing Integrity and Privacy criteria were not in scope. A buyer asking how agent output accuracy is controlled will not find the answer in this report.

Information security management systemISO/IEC 27001:2022CurrentCertificationExpires Mar 1, 2028

The information security management system covering the agentic operations platform and its operating team.

Covers

Ninety-three Annex A controls, statement of applicability version 4, three-year certificate with annual surveillance.

Explicitly excludes

Corporate IT, employee endpoints and the physical estate.

Issuer Acme Global — Chief Information Security Officer· Auditor Nordveld Certification AB· EV-TRUST-ISO27-01· Available on request

The year-one surveillance audit is 106 days past the date it should have been scheduled. A certificate stays valid until a body withdraws it, which is not the same as being in good standing.

Artificial intelligence management systemISO/IEC 42001:2023In progressCertificationTested Apr 22, 2026

Agent lifecycle management, the evaluation harness, adversarial testing and the change-release path.

Covers

Stage 1 documentation review completed. Stage 2 audit scheduled for 14 September 2026.

Explicitly excludes

Nothing is certified yet, so nothing is excluded yet.

Issuer Acme Global — Chief Information Security Officer· Auditor Nordveld Certification AB· Not releasable outside the organization

No certificate exists. Until Stage 2 closes, the estate is running 178 managed agents under a management system nobody outside the team has audited.

Privacy information management systemISO/IEC 27701:2019Not heldCertificationNo date

Not pursued.

Covers

None.

Explicitly excludes

None.

Issuer Acme Global — Group Data Protection Officer· Not releasable outside the organization

Privacy commitments rest on the Article 30 record and the signed data processing agreements. Neither is independently certified, and a questionnaire asking for 27701 gets a no.

UK National Cyber Security CentreCyber Essentials PlusLapsedCertificationExpires Feb 28, 2026

UK operating entity and the systems it administers.

Covers

Five technical control themes, verified by hands-on testing of a sample of devices.

Explicitly excludes

Non-UK entities.

Issuer Acme Global — UK Managing Director· Auditor Bardsey Assurance Ltd· Available on request

Lapsed 171 days ago. UK public-sector procurement treats a lapsed certificate as no certificate, so any bid requiring it fails today.

Payment Card Industry Data Security StandardPCI DSS v4.0Not heldCertificationNo date

Not pursued.

Covers

None.

Explicitly excludes

None.

Issuer Acme Global — Group Treasurer· Not releasable outside the organization

No cardholder data reaches any of the twelve towers today. The moment Order-to-Cash accepts a card payment this becomes a gap on day one, and nothing in the platform would flag it.

CREST-accredited, grey boxExternal application and network penetration testCurrentpenetration-testExpires Apr 8, 2027

The cockpit web application, the authentication path, the tenancy boundary and the evidence API.

Covers

Eleven testing days. Two medium and six low findings raised; both mediums remediated and retested on 6 May 2026.

Explicitly excludes

The agent runtime’s tool-calling surface and every model provider API.

Issuer Acme Global — Chief Information Security Officer· Auditor Hallward Red Team Ltd· EV-TRUST-PEN-01· Available on request

The agent runtime was explicitly out of scope. The most novel attack surface in the estate is the one this test did not touch.

Internal, modeled on OWASP LLM Top 10Prompt injection and tool-abuse assessmentIn progresspenetration-testTested Jun 2, 2026

Twenty-four attempts across injection, poisoning, exfiltration and tool abuse against the managed agent estate.

Covers

Recorded in full on the adversarial testing page, including the attempts that reached something.

Explicitly excludes

No third party has repeated any of it.

Issuer Acme Global — Head of Agent Platform· EV-TRUST-ADV-01· Available on request

Run by the team that built the agents. It is a useful engineering exercise and it is not independent assurance, and a procurement reviewer is right to score it as the former.

CREST-accredited, black boxInfrastructure penetration testLapsedpenetration-testExpires Mar 19, 2026

Perimeter, cloud configuration and identity provider integration.

Covers

Superseded by the 2026 H1 test. Retained because the remediation history is part of the record.

Explicitly excludes

Application layer.

Issuer Acme Global — Chief Information Security Officer· Auditor Hallward Red Team Ltd· Available on request
UK GDPR Article 35 / EU GDPR Article 35Data protection impact assessment — employee dataCurrentprivacy-assessmentExpires Feb 10, 2027

Agentic processing of employee data in the Hire-to-Retire tower, the role transition ledger and the works-council packs.

Covers

Necessity and proportionality, the lawful basis for each processing purpose, the rights of the data subject and the residual risk rating.

Explicitly excludes

Customer personal data, which sits under a separate assessment.

Issuer Acme Global — Group Data Protection Officer· EV-TRUST-DPIA-01· Available on request

Signed by the controller’s own data protection officer. No supervisory authority reviewed it, and none was consulted, because the residual risk was assessed as not high — an assessment made by the same organization that wanted the answer.

EU GDPR Article 35 and Article 22Data protection impact assessment — customer decisionsIn progressprivacy-assessmentTested May 28, 2026

Agent decisions affecting customers in the Order-to-Cash tower, including credit hold and dispute outcomes.

Covers

Draft circulated to Legal and Revenue Operations. The Article 22 analysis of solely automated decisions is the open section.

Explicitly excludes

Employee data.

Issuer Acme Global — Group Data Protection Officer· Not releasable outside the organization

Customer-facing agents are already running at volume while the assessment that should have preceded them is still in draft. That ordering is the finding.

Schrems II / EU standard contractual clausesTransfer impact assessment — United States and SingaporeExpiring soonprivacy-assessmentExpires Sep 27, 2026

Personal data reaching model providers and infrastructure hosted outside the European Economic Area.

Covers

Onward-transfer analysis for four sub-processors, with supplementary measures listed per destination.

Explicitly excludes

Any provider added after July 2025, of which there are two.

Issuer Acme Global — Group Data Protection Officer· EV-TRUST-TIA-01· Available on request

Expires in 40 days and two sub-processors added since it was written are not in it. Renewing it is not scheduled.

EU GDPR Article 6(1)(f)Legitimate interest assessment — sensing gridCurrentprivacy-assessmentExpires Jan 18, 2027

The twenty-six surfaces the sensing grid listens on and the balancing test behind each.

Covers

Purpose test, necessity test and balancing test recorded per surface, with the opt-out route named.

Explicitly excludes

Surfaces relying on consent rather than legitimate interest.

Issuer Acme Global — Group Data Protection Officer· Available on request
Placed through Lockridge BrokersCyber liability and technology errors and omissionsCurrentinsuranceExpires Dec 31, 2026

Group-wide cover including first-party incident response and third-party liability.

Covers

Twenty-five million dollar aggregate limit, one million dollar retention, incident response retainer included.

Explicitly excludes

Contractual penalties, regulatory fines where uninsurable, and any loss arising from a product recall.

Issuer Acme Global — Group Treasurer· EV-TRUST-INS-01· Available on request

The policy wording predates the agentic deployment. The insurer has not confirmed in writing that an autonomous agent action is a covered act, and nobody has asked.

Modeled on SR 11-7 model risk managementIndependent model risk reviewNot heldreviewNo date

Not pursued.

Covers

None.

Explicitly excludes

None.

Issuer Acme Global — Chief Risk Officer· Not releasable outside the organization

Every evaluation of every agent has been performed by the team that built it. A financial services buyer will ask for independent model validation and there is nothing to send.

ISO 22301 alignedBusiness continuity and disaster recovery exerciseCurrentreviewExpires Nov 12, 2026

Platform continuity: model provider outage, evidence store failure and a full region loss.

Covers

Three scenarios exercised with measured recovery, including the drill that failed and was rerun.

Explicitly excludes

A simultaneous loss of both model providers, which has never been exercised.

Issuer Acme Global — Director, IT Service Management· EV-TRUST-BCP-01· Available on request

Sixteen recovery drills are scheduled and eleven have been run. Eight of those eleven had an independent observer, three did not, and two missed their recovery objective. All of it, including the misses, is on the drills page.

Sub-processors

14 parties · 14 carry personal data · 4 carry special-category data · 2 with no agreement on file

PartyCategoryProcessing inDataAgreementAudit rightAssessedStanding

Primary model provider

Inference for every agent in the estate. Receives prompt content, which includes record extracts.

model-providerUSPersonalDPA-2025-014Report-based. No on-site audit right negotiated.41 days agoCritical

Approved with conditions. Zero-retention is contracted and attested annually; it is not independently verifiable by this platform.

This is the highest-exposure processor in the register and the one with the weakest audit right. Everything an agent reads passes through it.

Secondary model provider

Failover inference when the primary provider is unavailable or rate-limited.

model-providerUS · IEPersonalDPA-2025-019Report-based, SOC 2 Type II shared annually.41 days agoHigh

Approved. EU region available and used for EEA-origin traffic.

Applicant tracking vendor

Hosts candidate applications, assessment results and interview records.

saasUS · SGPersonal · onward transferDPA-2024-006Contractual on-site audit right, never exercised.3 months agoHigh

Approved with conditions. The vendor uses two onward processors for resume parsing and video interview hosting.

The audit right exists and has never been used. An unexercised audit right is a contract clause, not an assurance.

Resume parsing service

Extracts structured fields from uploaded resumes on behalf of the applicant tracking vendor.

saasUSPersonalnone on fileNone. This is an onward processor; the relationship is with the applicant tracking vendor, not with us.neverHigh

Not assessed. Identified from the vendor sub-processor page during the 2026 review, not from any notification.

A processor handling candidate resumes that we have never assessed and have no direct contract with. It was found by reading the vendor website.

Video interview platform

Hosts recorded and live interviews, and stores the recordings.

saasUS · DEPersonal · special categoryDPA-2025-021Report-based.3 months agoHigh

Approved with conditions. Facial analysis features are contractually disabled; the platform cannot verify they are off.

Video recordings are biometric-adjacent. Contractual disablement of facial analysis is asserted by the vendor and not observable from here.

Customer platform vendor

Hosts customer contact records, opportunity and quoting data.

saasUS · DE · SG · AUPersonalDPA-2023-002Report-based, ISO 27001 and SOC 2.12 months agoCritical

Approved. Regional instances configured. Sub-processor list refreshed twice since the last assessment.

Last assessed 348 days ago against a sub-processor list that has changed twice since.

Contact center vendor

Voice, chat and email handling, plus transcript generation and storage.

saasUS · DE · SG · AUPersonal · special category · onward transferDPA-2023-004Report-based.12 months agoCritical

Approved with conditions. Speech-to-text runs through an onward processor.

Transcripts carry whatever the customer says, including health and financial detail. Assessed as ordinary personal data.

Speech recognition service

Converts recorded calls to text for the contact center vendor.

model-providerUSPersonal · special categorynone on fileNone. Onward processor of the contact center vendor.neverHigh

Not assessed. Named in the vendor sub-processor list; no direct relationship exists.

Every recorded customer call in the estate passes through a processor we have never assessed.

Core HR vendor

Employee master, compensation, performance and payroll processing.

saasUS · NL · SGPersonalDPA-2024-001Contractual audit right plus annual third-party report.41 days agoCritical

Approved. EU pod confirmed for German and UK populations.

Infrastructure provider

Hosts the platform, the ledger, the warehouse and the evidence spine.

cloudUS · DE · UK · SG · AUPersonalDPA-2022-001Report-based, full compliance program published.41 days agoCritical

Approved. Regions pinned per record class; no cross-region replication configured outside the declared routes.

Marketing and analytics vendor

Campaign automation, digital analytics and attribution.

analyticsUSPersonalDPA-2026-002Report-based.41 days agoMedium

Approved under the EU-US Data Privacy Framework, certification verified February 2026.

Shared-service outsourcing partner

Human staff in the Singapore hub who handle escalated transactions across all four towers.

bpoSG · INPersonal · onward transferDPA-2024-008On-site audit right, exercised October 2025.10 months agoCritical

Approved with conditions. Delivery staff in a second country were disclosed during the on-site audit and are now named here.

Delivery from a second country was discovered during audit rather than disclosed in advance. The register now names it; the disclosure failure is not undone by that.

Background screening vendor

Right-to-work verification and criminal record checks where lawful.

saasUK · US · SGPersonal · special categoryDPA-2024-016Contractual audit right, exercised March 2026.41 days agoHigh

Approved. Criminal record checks are suppressed in jurisdictions where they are unlawful for the role.

German payroll bureau

Statutory payroll filing and social contribution reporting for the German entity.

payrollDEPersonalDPA-2023-011On-site audit right, exercised annually by the German entity.4 months agoHigh

Approved. Data stays in Germany throughout.

Actions

What a person has to do before the next buyer asks

Ordered by how visible the gap is to somebody outside the organization. Nothing on this list closes itself.

Attestations that are out of date

2

Cyber Essentials Plus · Infrastructure penetration test

Questions procurement will ask that we cannot answer

7

2.5 · 2.6 · 3.5 · 4.1 · 4.4 · 6.2 · 7.2

Sub-processors carrying data with no completed assessment

2

Resume parsing service · Speech recognition service

Certificates inside the renewal window

3

Schrems II / EU standard contractual clauses (40 days) · ISO 22301 aligned (86 days) · AICPA Trust Services Criteria (87 days)

Sub-processors with no signed data processing agreement on file

2

Resume parsing service · Speech recognition service

Live observability

Availability, month by month, component by component

48 incidents and 919 minutes of major outage over the window. A cell is amber where the month came in under its own target.

Uptime history

4 components × 7 months · 4 of 28 component-months below target · none of these figures is metered

ComponentTargetJan 2026Feb 2026Mar 2026Apr 2026May 2026Jun 2026Jul 2026Incidents
Cockpit application99.9%99.9499.9499.9799.8184m99.9699.9999.926
Agent runtime99.5%99.6299.6299.7198.94271m99.5599.6899.4162m15
Evidence API99.9%100.00100.0099.9899.96100.0099.99100.001
Model gateway99.0%99.4499.4499.12118m98.71340m99.3899.5199.2944m26

Measured by the platform’s own health check from two regions at one-minute intervals. There is no independent monitor.

Is policy and strategy coming to fruition

A standard vendor questionnaire, answered in place

The test for this page is not that it looks complete. It is that a procurement team can work top to bottom through 30 questions across 7 sections and finish without sending an email — including the 7 questions where the honest answer is that we do not hold what is being asked for.

Completed in place

40%

12 answered outright of 30.

Answered with a stated gap

11

The answer goes as far as the record goes and then says where it stops.

Cannot be answered

7

No certificate, no test, no metered data. Saying so is the answer.

Backed by a reference

18 of 30

30 of those open a surface inside this product.

Company and contract

3 questions · 2 answered · 1 partial · 0 cannot answer

1.1Who is the contracting entity, and where is it incorporated?Answered

The services are contracted through the group operating entity incorporated in Ireland, with local service schedules in the United States, the United Kingdom, Germany, France, Brazil, Singapore and Australia. The entity list and the schedule that applies to each country sits on the residency page.

page· open /residency· Owner Chief Procurement Officer· Reviewed Aug 17, 2026
1.2What is the notice period and what happens to service during it?Answered

Ninety days either side. Service continues unchanged for the whole notice period; the estate is frozen rather than degraded, and the exit plan starts on the day notice is received rather than at the next renewal.

page· EXT-01· open /portability· Owner Chief Procurement Officer· Reviewed Aug 17, 2026
1.3Do you carry cyber liability insurance, and does it cover autonomous agent actions?Partial

Yes to the first, not confirmed on the second. A $25 million cyber liability policy is in force to March 2027. Whether an incorrect decision taken autonomously by an agent falls inside the policy has been raised with the broker and has not been answered in writing. Treat agentic acts as uncovered until it is.

attestation· ATT-CYBER-INS· open /trust· Owner Group General Counsel· Reviewed Aug 17, 2026

Security

7 questions · 3 answered · 2 partial · 2 cannot answer

2.1Do you hold a current SOC 2 Type II report?Answered

Yes. Type II covering security, availability and confidentiality for the twelve months to 31 January 2026, issued by an independent firm. The report is released under non-disclosure on request; the scope, exclusions and opinion are stated on the trust center without one.

attestation· ATT-SOC2-T2· open /trust· Owner Chief Information Security Officer· Reviewed Aug 17, 2026
2.2Do you hold ISO/IEC 27001 certification and is the surveillance audit current?Partial

The certificate is current to October 2027. The annual surveillance audit was due on 4 May 2026 and has not been held; it is 46 days overdue and rescheduled for 28 July. A certificate stays valid through a late surveillance audit up to a limit, and we are inside that limit, but the honest position is that the certification is current and its supervision is late.

attestation· ATT-ISO27001· open /trust· Owner Chief Information Security Officer· Reviewed Aug 17, 2026
2.3When was the last independent penetration test, and did it cover the agent runtime?Partial

An independent test of the cockpit application and its APIs completed on 12 March 2026. The agent runtime was explicitly out of its scope. A second test covering the runtime, prompt handling and tool invocation is under way, and it is being run by our own red team rather than an independent firm, so it will not carry independent assurance when it reports.

attestation· ATT-PEN-2026H1· open /trust· Owner Chief Information Security Officer· Reviewed Aug 17, 2026
2.4How are prompt injection and tool abuse tested?Answered

Twenty-four adversarial attempts have been run against the estate across fifteen techniques, producing nineteen findings. Every attempt, what it reached and whether the finding is closed is published on the adversarial page, including the attempts that succeeded.

page· open /adversarial· Owner Head of Agent Platform· Reviewed Aug 17, 2026
2.5Do you hold Cyber Essentials Plus or an equivalent national scheme certification?Cannot answer

Not currently. The Cyber Essentials Plus certificate expired on 28 February 2026 and has not been renewed. Recertification is scheduled but not booked. If this is a mandatory requirement of your process we do not meet it today.

attestation· ATT-CE-PLUS· open /trust· Owner Chief Information Security Officer· Reviewed Aug 17, 2026
2.6Are you PCI DSS compliant?Cannot answer

No, and it is out of scope. The estate does not store, process or transmit cardholder data at any station. If your process requires a PCI attestation regardless of scope, we cannot provide one.

attestation· ATT-PCIDSS· open /trust· Owner Chief Information Security Officer· Reviewed Aug 17, 2026
2.7How is administrative and agent access controlled?Answered

Identity is federated through a single provider with enforced multi-factor authentication. Agents hold service credentials scoped to the authority granted to them, and 309 authority grants are enumerated with the value ceiling and second-signature rule attached to each. The duties page shows every pair of duties that must not be held together and where the estate currently breaches that.

page· open /duties· Owner Chief Information Security Officer· Reviewed Aug 17, 2026

Privacy and data protection

6 questions · 2 answered · 3 partial · 1 cannot answer

3.1Have you completed a data protection impact assessment for the agentic processing?Partial

For the hire-to-retire tower, yes — completed and signed on 19 February 2026. For order-to-cash the assessment is still in progress while the agents in that tower are already running in production. That sequence is the wrong way round and it is recorded as such rather than presented as work in flight.

attestation· ATT-DPIA-O2C· open /trust· Owner Data Protection Officer· Reviewed Aug 17, 2026
3.2Provide your sub-processor list and your notification commitment for changes.Answered

The full sub-processor register is published on the trust center with the purpose, the record classes each one touches, the processing locations, the data processing agreement reference and the last assessment outcome. Thirty days of written notice before any addition, with a right to object.

registry· open /trust· Owner Data Protection Officer· Reviewed Aug 17, 2026
3.3Where is personal data processed, and how are international transfers handled?Partial

Processing locations are published per record class on the residency page. Transfers out of the EU rely on standard contractual clauses supported by a transfer impact assessment, and that assessment expires in 40 days. Two sub-processors added since it was written are not covered by it.

attestation· ATT-TIA-US-SG· open /residency· Owner Data Protection Officer· Reviewed Aug 17, 2026
3.4Is customer or employee data used to train any model?Answered

No. Every provider endpoint in the registry is contracted with training excluded and zero retention. The self-hosted models never leave our tenancy at all, and special-category personal data is routed only to those. Each entry in the model registry states its data boundary and its training position individually.

registry· open /models· Owner Data Protection Officer· Reviewed Aug 17, 2026
3.5Do you hold ISO/IEC 27701 or an equivalent privacy information management certification?Cannot answer

No. It has not been pursued and no timetable exists. The privacy programme runs against the data protection regulation directly rather than against a certified management system.

attestation· ATT-ISO27701· open /trust· Owner Data Protection Officer· Reviewed Aug 17, 2026
3.6How long is data retained, and can a data subject request be satisfied end to end?Partial

Retention is set per record class and published. Deletion propagates through the operational stores. It does not propagate through the nightly extracts written to our own object storage, which currently have no retention policy configured, so a satisfied request today can leave a copy behind in an export.

page· PRT-DECISIONS· open /retention· Owner Data Protection Officer· Reviewed Aug 17, 2026

AI governance

5 questions · 2 answered · 1 partial · 2 cannot answer

4.1Do you operate a certified AI management system?Cannot answer

Not yet. ISO/IEC 42001 is at stage 2 audit, booked for 14 September 2026. Until that audit passes there is no independent assurance over the AI management system, and no amount of internal documentation substitutes for it.

attestation· ATT-ISO42001· open /trust· Owner Chief Risk Officer· Reviewed Aug 17, 2026
4.2Provide model cards for every model in production use.Answered

Twelve models are registered. Each carries its provider, version, modality, hosting location, data boundary, training position, contract type, the towers and agent count that call it, its lifecycle status and its named substitute. Three are self-hosted open weights, two are retired and kept visible, one is under a published deprecation notice.

registry· open /models· Owner Head of Agent Platform· Reviewed Aug 17, 2026
4.3What happens when an underlying model is deprecated or repriced?Partial

Every model has a named substitute except three. Eight of the nine named substitutions have been tested against the golden sets; one has not. The untested one is the embedding model, and replacing it means re-embedding the entire retrieval corpus — work that has never been scoped or costed. One model is under a hard end-of-life date 135 days away with 168 agents still calling it and no named owner for the cutover.

registry· MDL-ABX-EMB· open /models· Owner Head of Agent Platform· Reviewed Aug 17, 2026
4.4Has an independent party validated the models or the evaluation suites?Cannot answer

No. Every evaluation in the estate runs against golden sets written by the team that built the agents. A passing suite shows an agent behaves the way we specified; it does not show that the specification is right. No model risk management review has been performed by anybody outside that team.

attestation· ATT-MRM· open /evaluations· Owner Chief Risk Officer· Reviewed Aug 17, 2026
4.5How is autonomy granted and withdrawn?Answered

Agents move through five stages against evidence gates, and demotion is armed automatically when a gate stops holding. The full stage history for every managed agent, including every promotion and every demotion with the evaluation run behind it, is published. 178 agents are under lifecycle management and 1,183 are not, which is stated on the page rather than left to be discovered.

page· open /lifecycle· Owner Head of Agent Platform· Reviewed Aug 17, 2026

Resilience

3 questions · 2 answered · 1 partial · 0 cannot answer

5.1Provide uptime history against target for the last six months.Partial

Six months of monthly availability for four components against their targets, with incident counts and major-outage minutes. It is self-reported from our own monitoring. There is no independent monitor and no third party has verified any of these figures.

registry· open /trust· Owner Head of Agent Platform· Reviewed Aug 17, 2026
5.2When was your business continuity plan last tested?Answered

The continuity exercise aligned to ISO 22301 ran on 12 May 2026 across three scenarios — model provider outage, evidence store failure and full region loss. Separately, sixteen recovery drills are scheduled and eleven have been run; two of those missed their recovery objective and three had no independent observer. Every drill, including the two misses, is published.

attestation· ATT-BCP-TEST· open /drills· Owner Chief Operating Officer· Reviewed Aug 17, 2026
5.3What is your single largest supplier concentration, and what is the plan?Answered

Six of every ten inference dollars go to one model provider. Three of the five workloads with that provider have a tested route to a second provider. The embedding workload does not, and that is the concentration that matters rather than the headline share.

registry· VND-ABX· open /models· Owner Chief Procurement Officer· Reviewed Aug 17, 2026

Portability and exit

3 questions · 0 answered · 2 partial · 1 cannot answer

6.1In what formats can we extract our data, and how long does it take?Partial

Fourteen asset classes in CSV, JSON, JSONL, Parquet, Markdown and PDF — all open, none proprietary. Four have a live route or a nightly job; ten are produced by hand from a database query. The full extract is planned at fourteen days and that assumes the hand-produced ones go right first time.

page· open /portability· Owner Head of Data and Analytics· Reviewed Aug 17, 2026
6.2Has the exported data ever been restored into another system?Cannot answer

Two of fourteen asset classes have been read outside the product — the evidence packs and the trust register, both through live routes an auditor has used. The other twelve have never been imported into anything. No parallel run and no restore verification has ever been performed. This is the weakest point in the exit plan and the plan depends on it.

page· EXT-09· open /portability· Owner Head of Internal Audit· Reviewed Aug 17, 2026
6.3Is there a documented run-book handover and a deletion certificate at the end?Partial

The run-book is generated from the same tables the product reads, so it cannot go stale, and it has never been handed to anyone outside the team that wrote it. Deletion produces a signed certificate listing every store; backups age out over 35 days rather than being deleted immediately, and the certificate says so.

page· EXT-06· open /portability· Owner Head of Global Business Services· Reviewed Aug 17, 2026

Sustainability

3 questions · 1 answered · 1 partial · 1 cannot answer

7.1Report the energy and carbon footprint of inference for the services we consume.Partial

Reported weekly for the estate, for each of the twelve towers and for each of the twelve models, with a five-week trend. It is derived from call volume by arithmetic, not metered. No provider in the registry discloses metered energy per request, so the ranking between towers is meaningful and the absolute kilowatt hours are an estimate.

page· open /inference· Owner Head of Agent Platform· Reviewed Aug 17, 2026
7.2Can you provide metered, provider-attested energy consumption per transaction?Cannot answer

No. None of the three model providers exposes per-request energy, and the self-hosted models run on shared accelerators where consumption is not attributed per tenant. Anyone claiming a metered per-transaction figure for hosted inference today is estimating it the same way we are and calling it something else.

· open /inference· Owner Head of Agent Platform· Reviewed Aug 17, 2026
7.3Is experience reported alongside throughput, or only efficiency?Answered

Eighteen employee and customer measures are published, each paired with the throughput measure it sits beside. Seven of them have moved the wrong way while throughput improved, including the share of customers who reached a person when they asked, which fell from 69 percent to 44.2.

page· open /experience· Owner Chief Operating Officer· Reviewed Aug 17, 2026

What this page is, and what it is not

A security certification and a penetration test are organizational attestations. The product can house them, track their currency and surface their scope; it cannot manufacture them. Present the trust center as the place they live, never as evidence that they exist.

Concretely: of the 16 records above, 7 are current, 2 have lapsed and 3 are not held at all. The uptime history is drawn from the modeled estate and is not metered by an independent monitor. The sub-processor register lists 14 parties, of which 2 have never been assessed and 2 have no agreement reference on file. None of that is hidden behind a request form, and none of it should be read as an audit.