Data handling
Operational data uses an approved intake path and contracted purpose. Public forms are limited to inquiry and scoping. Client data is not sold.
Buyer Trust Center
This page distinguishes implemented safeguards, contractual boundaries, and items that may be evaluated in the future. It is a buyer-assurance summary, not an independent audit, certification, third-party attestation, penetration test, uptime commitment, SLA, or substitute for a signed agreement.
Operational data uses an approved intake path and contracted purpose. Public forms are limited to inquiry and scoping. Client data is not sold.
Connector credentials are sealed with AES-256-GCM. Transport security, deployment secrets, and storage controls are reviewed as part of the qualified security scope.
Tenant-scoped application roles, administrator-controlled connectors, and human approval gates limit access and downstream action.
Tenant context is enforced in authenticated workflows. Isolation concerns are treated as Critical and investigated before normal processing continues.
Material agent preparation, approval, rejection, native draft, provider outcome, and failure events are recorded in append-only database tables.
Retention is agreed by engagement and data category. Export, return, or deletion requirements are documented in the order form or SOW before sensitive intake.
Security reports route to the published security contact and target a same-business-day initial response during the current support window.
The current service is principal-led. Continuity, export, deletion, support coverage, and any required backup-resource commitments must be agreed in writing.
| Item | Current status | Boundary |
|---|---|---|
| SOC 2 | Not completed; no certification or active audit is claimed. | Future independent attestations will be evaluated against customer and contractual requirements. |
| ISO 27001 | Not completed; no certification or active audit is claimed. | Future independent attestations will be evaluated against customer and contractual requirements. |
| FedRAMP | Not completed; no authorization or active assessment is claimed. | Future independent attestations will be evaluated against customer and contractual requirements. |
| Independent penetration test | Not completed; no active test or third-party attestation is claimed. | Future independent attestations will be evaluated against customer and contractual requirements. |
| Independent security audit | Not completed; no active audit or third-party attestation is claimed. | Future independent attestations will be evaluated against customer and contractual requirements. |
| Standard DPA | Not published | Availability and final terms must be confirmed during contracting. |
| Subprocessor list | Not published | Engagement-specific provider use must be confirmed before sensitive intake. |
| Disaster-recovery commitment | Not independently verified or contracted by default | No recovery objective or continuity guarantee is implied. |
| 24x7 support / uptime SLA | Not included by default | Only applies when expressly stated in a signed agreement. |
Vulnerability reports and security questionnaires: ian@pwlogicongroup.com. Do not include sensitive exploit details in an initial unencrypted message.