Security

Every statement on this page is either a measurement taken on the production system, with the report-card row it rests on, or a plain statement that something is not available yet. This page was cut against Green-Out v15 on 2026-09-14; it is a snapshot, not a live read.

How decisions are recorded

What happens to a governed decision the moment it is made.

  • Every governed decision is recorded as a receipt that is signed twice, with ML-DSA-65 (FIPS 204) and SLH-DSA-SHAKE-256f (FIPS 205), so a receipt stays checkable after either scheme is broken.

    Measured on the production system; report card row 35 (LIVE), row 52 (LIVE).

  • Receipts are chained: each one carries the hash of the receipt before it, and the dashboard compares every link in your own browser, marking each row checked or broken. That catches a changed or missing link; checking each hash against the receipt's own contents needs the verifier.

    Measured on the production system; report card row 53 (LIVE).

  • A governed workspace action is anchored to your chain before it is recorded. If the anchor fails, the action is refused rather than recorded unanchored.

    Measured on the production system; report card row 54 (LIVE).

  • A malformed or empty governance request is refused. Nothing is approved by default.

    Measured on the production system; report card row 6 (LIVE).

How your data is kept apart

What separates your tenant from every other tenant, and what is encrypted.

  • Tenants are separated in the database itself: row-level security is enforced on billing records, and what the dashboard shows about your tenant is measured against the production database, not inferred.

    Measured on the production system; report card row 38 (LIVE), row 45 (LIVE).

  • Workspace transcripts are stored encrypted at rest under a key bound to your tenant, each turn bound to its receipt, and you can delete them yourself.

    Measured on the production system; report card row 61 (LIVE).

  • The usage meter on your dashboard is trust-gated: a figure is shown as measured only from the moment the meter itself was proven, and is labelled otherwise before that.

    Measured on the production system; report card row 58 (LIVE).

How you can check us

What you can verify yourself today, and what you cannot yet.

  • The export bundle you download carries the post-quantum signature, so the records can be checked outside our systems.

    Measured on the production system; report card row 36 (LIVE).

  • Not available yet: checking a receipt's signatures yourself, outside our systems. The in-browser check today covers the hash links between receipts; signature verification by customers is being built.

    Stated as a gap; report card row 47 (PARTIAL).

  • Not available yet: an independently published chain head that lets a third party confirm our records without trusting us.

    Stated as a gap.

  • Not available yet: a third-party audit or certification (SOC 2, ISO 27001). None has been completed. The statements on this page are our own measurements.

    Stated as a gap.

How people sign in

What is available at the door, and what is not.

  • Not available yet: single sign-on (SAML). Sign-in is an emailed magic link at every tier; no identity-provider configuration is accepted or stored.

    Stated as a gap; report card row 76 (LIVE).

  • Not available yet: a second factor at sign-in, and IP allowlisting.

    Stated as a gap.

Backups and continuity

What exists, and what does not yet.

  • Not available yet: an off-site, encrypted backup of the governance chain. Local snapshots are taken; the off-site copy waits on a custody decision.

    Stated as a gap; report card row 26 (PARTIAL).

Where to go from here

The privacy policy says what is collected and why. The data processing addendum sets out roles, sub-processors, retention, deletion and incident notice. Security questions: security@logirootai.com.