Trust Center
Trust, itemized.
We hold no certifications yet, and we won't pretend otherwise. What we have instead is an architecture you can inspect — every control below is real, running, and stated precisely.
Control inventory · 23 July 2026
01
The gate.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| Decision path | Approval is a property of the database. The content state machine is a single guarded function; a decision requires the exact latest draft, the right person, the right role. Illegal transitions don’t get logged and forgiven — they raise errors. The AI side can propose; it cannot decide, and it cannot publish. | ENFORCED | |
| Immutable versions | Drafts are immutable and versioned. A revision creates a new version; prior verification, QA, and approval do not carry forward. | ENFORCED | |
| Exact approval record | Every approval decision is recorded against the latest exact draft and written into the hash-chained audit record. | ENFORCED |
FIG. 02 lives on the Security page; this inventory does not duplicate it.
02
Isolation & access.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| Organization boundary | Organization-scoped tables enforce Row-Level Security. Browser roles can read only the rows their membership and role permit. | ENFORCED | |
| Service authority | Service authority is held by the server-side worker. No browser role holds service credentials. | ENFORCED | |
| Founder access | Founder-only control surfaces require a server-owned claim that a browser cannot self-assign. | ENFORCED |
03
Evidence & audit.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| Audit chain | Every action is on the record: an append-only, hash-chained audit log of every transition and every decision, by authenticated actor. | ENFORCED | |
| Minimized records | Approval comments remain on the decision record but are redacted from audit diffs. Operational evidence excludes secrets, source content, and customer data. | ENFORCED | |
| Erasure re-chain | When erasure requires audit redaction, a dedicated maintenance role re-chains the affected rows and the erasure certificate stores both the old and new chain roots. | ENFORCED |
04
Data lifecycle.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| Full export | The built export path produces a deterministic full archive with a manifest, JSON data, owned assets, and SHA-256 evidence. Production delivery remains held until email transport passes the no-tracking gate. | LIVEDELIVERY HELD | |
| Voice subset | The built voice-only export contains the voice card, patterns, and writing samples. Production delivery is held by the same email-transport gate. | LIVEDELIVERY HELD | |
| Deletion | The built deletion path applies a 7-day grace period before erasure; undo remains available during that window. Production execution remains held pending final copy and provider proofs. | LIVEEXECUTION HELD | |
| Erasure certificate | Completed erasure writes a certificate with purge counts, storage deletion counts, provider confirmations, chain roots, and the backup purge deadline. | ENFORCED | |
| LLM traces | 90 days | ENFORCED | |
| Anonymous report leads | 12 months | ENFORCED | |
| Backups | 35-day ceiling | LIVE | |
| Restore rule | A restored service cannot accept traffic until the erasure ledger is replayed and the residual-data scan passes. | ENFORCED |
05
Infrastructure.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| Primary stack | Crafted Virtue is self-hosted on owned infrastructure in the European Union: an isolated database stack, worker fleet, and private research system. | LIVE | |
| Offsite backup | Restic encrypts offsite backups before transfer to a dedicated least-privilege storage sub-account in a separate European location. | LIVE | |
| Dead-man monitoring | Independent dead-man checks expect production signals and alert on a missed run without relying on the monitored host. | LIVE | |
| Direct ports | Direct application, database, storage, and worker container ports are closed to the public network; public traffic reaches the stack only through the owned reverse proxy. | LIVE | |
| Fetch safety | Public-source fetches are checked at the application and network layers for unsafe schemes, credentials, ports, DNS answers, redirects, and private, loopback, link-local, metadata, multicast, and reserved destinations. | ENFORCED |
06
Privacy posture.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| Trackers | This site installs zero third-party trackers. Not minimized — zero. First-party only. | LIVE | |
| Analytics | No analytics tags are installed. | LIVE | |
| Fonts | The site serves its fonts first-party. | LIVE | |
| Consent banner | There is no cookie banner because the site sets no tracking cookies and loads no third-party trackers. | LIVE | |
| Email transport | Transactional email currently transits a provider that rewrites links; replacing this is in progress | LIVEOPEN DEFECT |
07
Providers & subprocessors.
Provider capability never implies product permission. External services sit behind owned boundaries, and release switches remain separate from provider availability.
| Provider category | Role | Region | Status |
|---|---|---|---|
| Owned infrastructure | Application, database, worker, and private research hosting | European Union | LIVE |
| Encrypted offsite backup storage | Encrypted backup storage | European Union, separate location | LIVE |
| Transactional email provider | Account, recovery, and operational email | Transfer detail in preparation with counsel | LIVEOPEN DEFECT |
| Customer model processors | Text and media processing | No real customer data permitted pending processor review | HELD |
| Customer DPA | Controller–processor terms and subprocessor schedule | in preparation with counsel. | IN PREPARATION |
Provider names and transfer details publish only after Ian confirms disclosure and counsel completes the register.
08
What we don't have yet.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| SOC 2 | We do not hold SOC 2 certification. | NOT HELD | |
| ISO 27001 | We do not hold ISO 27001 certification. | NOT HELD | |
| Article 42 GDPR | We do not hold an Article 42 GDPR certification. | NOT HELD |
Certification follows revenue and an entity to audit; the controls above don't wait for either.
09
Contact & disclosure.
| Control | Current state | Status | Inspect |
|---|---|---|---|
| security.txt | Our disclosure policy is published at /.well-known/security.txt. | LIVE | |
| Disclosure contact | Security reports: hello@craftedvirtue.com. | LIVE |