Security
Every statement on this page is either a measurement taken on the production system, with the report-card row it rests on, or a plain statement that something is not available yet. This page was cut against Green-Out v15 on 2026-09-14; it is a snapshot, not a live read.
How decisions are recorded
What happens to a governed decision the moment it is made.
Every governed decision is recorded as a receipt that is signed twice, with ML-DSA-65 (FIPS 204) and SLH-DSA-SHAKE-256f (FIPS 205), so a receipt stays checkable after either scheme is broken.
Measured on the production system; report card row 35 (LIVE), row 52 (LIVE).
Receipts are chained: each one carries the hash of the receipt before it, and the dashboard compares every link in your own browser, marking each row checked or broken. That catches a changed or missing link; checking each hash against the receipt's own contents needs the verifier.
Measured on the production system; report card row 53 (LIVE).
A governed workspace action is anchored to your chain before it is recorded. If the anchor fails, the action is refused rather than recorded unanchored.
Measured on the production system; report card row 54 (LIVE).
A malformed or empty governance request is refused. Nothing is approved by default.
Measured on the production system; report card row 6 (LIVE).
How your data is kept apart
What separates your tenant from every other tenant, and what is encrypted.
Tenants are separated in the database itself: row-level security is enforced on billing records, and what the dashboard shows about your tenant is measured against the production database, not inferred.
Measured on the production system; report card row 38 (LIVE), row 45 (LIVE).
Workspace transcripts are stored encrypted at rest under a key bound to your tenant, each turn bound to its receipt, and you can delete them yourself.
Measured on the production system; report card row 61 (LIVE).
The usage meter on your dashboard is trust-gated: a figure is shown as measured only from the moment the meter itself was proven, and is labelled otherwise before that.
Measured on the production system; report card row 58 (LIVE).
How you can check us
What you can verify yourself today, and what you cannot yet.
The export bundle you download carries the post-quantum signature, so the records can be checked outside our systems.
Measured on the production system; report card row 36 (LIVE).
Not available yet: checking a receipt's signatures yourself, outside our systems. The in-browser check today covers the hash links between receipts; signature verification by customers is being built.
Stated as a gap; report card row 47 (PARTIAL).
Not available yet: an independently published chain head that lets a third party confirm our records without trusting us.
Stated as a gap.
Not available yet: a third-party audit or certification (SOC 2, ISO 27001). None has been completed. The statements on this page are our own measurements.
Stated as a gap.
How people sign in
What is available at the door, and what is not.
Not available yet: single sign-on (SAML). Sign-in is an emailed magic link at every tier; no identity-provider configuration is accepted or stored.
Stated as a gap; report card row 76 (LIVE).
Not available yet: a second factor at sign-in, and IP allowlisting.
Stated as a gap.
Backups and continuity
What exists, and what does not yet.
Not available yet: an off-site, encrypted backup of the governance chain. Local snapshots are taken; the off-site copy waits on a custody decision.
Stated as a gap; report card row 26 (PARTIAL).
Where to go from here
The privacy policy says what is collected and why. The data processing addendum sets out roles, sub-processors, retention, deletion and incident notice. Security questions: security@logirootai.com.