TRUST CENTRE

Trust belongs
in the architecture.

Client environments contain sensitive context. Our approach starts with clear boundaries, deliberate access and evidence behind every action.

Explore the design principles
SECURITY BY DESIGN

Give people and agents permissions appropriate to their work.

Explore the client controls libraryIdentity, endpoints, backups, vulnerabilities and licensing checks in Alignr Baseline.
SOC 2PendingPending

SOC 2 is pending. No completed SOC 2 report or certification is claimed.

01 / CLEAR BOUNDARIES

Every client.
Their own context.

Client information should stay within its intended boundary. Our design connects each request to the right organisation and the permissions of the person or agent making it.

Product design principle
TechnicianAgent
Identity + role + client scope
NorthstarAuthorised context
Other clientsOutside this request
02 / DELIBERATE ACTION

Reading context.
Changing environments.
Different permissions.

Knowing what needs attention is one step. Authorising a change is another. The intended workflow keeps the evidence, approval and outcome connected, with a technician in control.

Evidence, access and accountability
THE ACTION TRAIL
EvidenceAccount disabled · licence assigned
ApprovalTechnician reviews the proposed change
ActionSupported remediation is requested
VerificationResult checked against the environment
ASSURANCE IS A JOURNEY

Build the controls.
Show the evidence.

We want assurance to be something you can examine. SOC 2 is pending. As controls and supporting materials become available, this Trust Centre will distinguish implementation from independently verified assurance.

01Design principlesPublished here
02Control evidenceTo be published
03SOC 2Pending
SECURITY & GOVERNANCE COVERAGE

The questions that deserve clear answers.

These are the security topics covered by our product review. Status labels distinguish design requirements from verified implementation.

Tenant-level isolation

Design requirement

Preserve client boundaries across evidence, portal views and agent access.

Role-based access control

Design requirement

Scope people and agent access to authorised client records and actions.

Encryption at rest

To confirm

Publish the implemented storage encryption and key-management details.

Encryption in transit

To confirm

Publish the supported transport protections and configuration.

Permission-aware AI

Design requirement

Apply source-record permissions before returning context to an agent.

Audit logs, versioning and rollback

To confirm

Document which activities and changes are recorded, retained and reversible.

Customer data and model training

Policy to publish

State how customer data is handled by the platform and any AI providers.

SOC 2

Pending

No completed SOC 2 report is claimed.

ISO 27001

Not confirmed

No certification or completion date is claimed.

Availability and SLA

Terms to publish

Confirm the service commitment and applicable exclusions.

Draft privacy and legal documents
SECURITY DOCUMENTATION

Assurance you can examine.

We’ll distinguish design intent from implemented controls and independently verified assurance. These materials have not been published on this site yet.

Security architecture & controlsNot yet published
Information security policyNot yet published
Incident response policyNot yet published
Data processing & hosting detailsNot yet published
Retention & deletion policyNot yet published
Disaster recovery & business continuityNot yet published
SOC 2 report — pendingNot yet published
Cybersecurity insurance documentationNot yet published
CONTEXT WITH BOUNDARIES

The same principles.
For people and agents.

Explore how our MCP-first direction brings client context into agent workflows.

Explore agent access