Trust and security
What we can prove, and what we cannot.
No SOC 2. No ISO 27001. No completed penetration test. Here is what there is instead, with every control's real state.
This page exists to be forwarded. Sooner or later your biggest customer's IT person wants to know what you are running, and the useful answer is a register with states — not adjectives.
Every account also gets its own Trust page inside the product, and a claim only appears on it while the control behind it is enforced. If one regresses the claim comes off by itself, without anybody rewriting a page.
Every control, with its real state — including the ones we have not done.
The control register.
Twenty-four controls, with what each one is and where it has got to. Two are checked LIVE on every load rather than asserted — if the audit chain or the integration registry fails its check, the state changes without anyone editing anything.
| ID | Control | Note | State |
|---|---|---|---|
| SEC-016 | Signed append-only ledger + witness | Detects an in-place edit, a deletion or a reorder | Live check |
| SEC-015 | Integration Registry drift guard | Every external integration stays a registered asset | Live check |
| SEC-006 | Cross-tenant isolation | Your Hub is scoped by the session that resolved you, not by a filter in the interface | Enforced |
| SEC-010 | Operator routes pruned online | The hosted plane serves the customer surface only — operator routes are absent, not merely gated | Enforced |
| SEC-005 | AI never writes money | Money is deterministic. No model writes a financial field | Enforced |
| SEC-002 | Output-leak gate | The serving boundary scans for system-prompt and credential leakage | Enforced |
| SEC-012 | Per-tenant vaulted tokens | Connector credentials live in an encrypted vault, per tenant | Enforced |
| SEC-014 | Connectors untrusted by default | An outbound connector is least-privilege and cannot spend | Enforced |
| SEC-017 | Memory-poisoning control | An explicit control with its own evaluation, not an assumption | Enforced |
| SEC-019 | Pinned dependencies + CVE scan | A CI gate on pinned deps, plus an owner-run vulnerability scan | Enforced |
| SEC-020 | Professional penetration test | Not done. It is a gate we set for ourselves before serving any live AI model to a customer | Pending |
| SEC-021 | Key rotation infrastructure at scale | Not built. Keys are vaulted; rotating them at scale is not automated | Pending |
| SEC-022 | Provider DPAs — no-training and isolation | Not signed. One of the two things holding the hosted assistant switched off | Pending |
| SEC-023 | Self-hosted open-weight model | Not built. The IP tier that would remove a third-party model from the path entirely | Pending |
That is fourteen of the twenty-four, chosen because they are the ones a customer's reviewer asks about — and all four pending controls are here, in full, because a register that shows only its passes is a brochure. The complete list, with the live checks running, is on your own Trust page once you have an account.
Where your data goes, and what crosses.
We will not tell you your data is stored in Australia. The hosted service for Australian customers runs in Singapore on Render, with a dedicated database and disk of its own, and the providers below process outside Australia. It is here in plain sight because it is the question a reviewer asks first, and it is in the privacy policy as well.
| Service | What it does | What crosses |
|---|---|---|
| Render | Hosts the service. The Australian plane runs in the Singapore region with its own disk and its own token. | Site artifacts and service configuration — never customer stores or Core content. |
| Neon | The hosted database, per plane. | Your account, billing and delivery records — the hosted plane owns them. |
| Clerk | Sign-in. | Sign-in identity claims and per-tenant sessions. Nothing else. |
| Stripe | Subscriptions, checkout and invoices. | Billing identity and subscription data — never your content. We never see or store your card. |
| Cloudflare | DNS and edge for the public addresses. | DNS records and cache directives only. |
These boundary statements are not written for this page. They come from the runtime's own Integration Registry, where every external integration is a registered asset with the honest statement of what crosses it — and SEC-015 checks that register for drift on every load.
What we will not claim.
These phrases sit on a denylist that a test enforces, so nobody here can write one into a customer-facing claim by accident. Not even by hand.
“Bank-grade security.”
It means nothing, and it is on the denylist. What we have instead is a register with states, above.
“SOC 2 certified.” “ISO 27001.” “Penetration tested.”
We hold none of them and the pen test is a named pending control, SEC-020. When that changes we will say so with a date and an auditor.
“Your data stays in Australia.”
It does not. The service runs in Singapore and the providers above process overseas. An Australian company is not the same thing as Australian data residency, and we will not let the first imply the second.
“Multi-factor authentication.”
A hosted account signs in with a one-time code emailed to you. That is better than a reused password and it is not a second factor, so we do not call it one.
The same phrases are enforced in the product, not just avoided on this page. saas_security DO_NOT_CLAIM · a test fails the build
If you find something, tell us.
Send it to security@mipartner.com.au. Tell us what you found and how you found it, and you will get a real answer from the person who fixes it.
We do not run a bounty programme and we are not going to pretend otherwise. What you will get is an acknowledgement, a fix or a reason, and — if it changes what is true on this page — the register above updated to say so.