Skip to main content

Trust Center

Inspect the evidence state before the architecture review.

Public summaries link directly to their current source. Scoped items require deployment context and document approval. Roadmap items are identified explicitly and are not presented as available evidence.

This inventory records website publication state, not certification completion. Contractual, customer-specific, or security-sensitive material is shared only after scope and approval review.

Inventory reviewed: 29 August 2026

Public summary

Certification and assurance status

Dated status, target, scope, and available review material for each assurance program. No certification is presented as complete unless it is held.

Scope
Iftah organization and governed platform
Owner
Security and compliance
Last reviewed
21 August 2026
View public summary
Public summary

Architecture security

Public control overview covering network isolation, encryption, identity, policy enforcement, and audit boundaries. Deployment-specific detail is scoped for review.

Scope
Reference deployment patterns
Owner
Platform security
Evidence state
Public summary
View public summary
View 10 more evidence objectsعرض 10 عناصر أدلة إضافية
Public summary

Data-flow and trust boundaries

Sanitized topology showing control-plane metadata and customer-contained prompt, file, vector, and model paths.

Scope
Customer cloud, private cloud, on-premises, and air-gap patterns
Owner
Platform architecture
Evidence state
Public summary
View public summary
Public summary

Encryption responsibility model

Public summary of encryption in transit and at rest, including the customer-owned identity and key boundary.

Scope
Platform and customer deployment boundary
Owner
Platform security
Evidence state
Public summary
View public summary
Public summary

Identity and access management

SSO, RBAC, customer identity-provider, and default-deny authorization overview. Configuration detail is deployment-specific.

Scope
Human, application, and agent access
Owner
Platform security
Evidence state
Public summary
View public summary
Scoped request

Logging and audit evidence

Public description of decision, access, deployment, and operational evidence. Sample packages require workload and retention scoping.

Scope
Governance and deployment audit events
Owner
Platform operations
Evidence state
Scoped request
Request scoped review
Roadmap

Vulnerability management

A publishable policy summary and gated testing evidence are being prepared for security and legal approval.

Scope
Product and delivery lifecycle
Owner
Product security
Evidence state
Roadmap

Not yet published

Public summary

Privacy

The public privacy policy is available now. Contractual privacy material and deployment-specific processing terms remain part of procurement review.

Scope
Website and commercial engagement
Owner
Legal and privacy
Evidence state
Public summary
View public summary
Roadmap

Subprocessors

A public list and change-notification process require legal and delivery approval before publication.

Scope
Website, commercial, and delivery services
Owner
Legal and delivery
Evidence state
Roadmap

Not yet published

Roadmap

Availability and service status

Service definitions, status reporting, and incident-history publication are not yet available as a public evidence object.

Scope
Contracted service by deployment model
Owner
Service operations
Evidence state
Roadmap

Not yet published

Roadmap

Responsible disclosure

A public reporting policy and security contact workflow require security and legal approval before publication.

Scope
Public product security reports
Owner
Product security and legal
Evidence state
Roadmap

Not yet published

Scoped request

Regulatory control mappings

Regulatory control mapping is scoped to the customer's jurisdiction, sector, and deployment. Availability is confirmed during the review rather than implied publicly.

Scope
Customer jurisdiction and deployment
Owner
Security and compliance
Evidence state
Scoped request
Request scoped review

Need a deployment-specific evidence pack?

Tell us the jurisdiction, deployment pattern, framework, and reviewer role. We will confirm what is public, what can be shared under review, and what is not yet available.

Start a Trust Review