Buyer Trust Center

Current controls, procurement documents, and attestation status in one place.

This page distinguishes implemented safeguards, contractual boundaries, and items that may be evaluated in the future. It is a buyer-assurance summary, not an independent audit, certification, third-party attestation, penetration test, uptime commitment, SLA, or substitute for a signed agreement.

Data handling

Operational data uses an approved intake path and contracted purpose. Public forms are limited to inquiry and scoping. Client data is not sold.

Encryption

Connector credentials are sealed with AES-256-GCM. Transport security, deployment secrets, and storage controls are reviewed as part of the qualified security scope.

Access control

Tenant-scoped application roles, administrator-controlled connectors, and human approval gates limit access and downstream action.

Tenant boundaries

Tenant context is enforced in authenticated workflows. Isolation concerns are treated as Critical and investigated before normal processing continues.

Auditability

Material agent preparation, approval, rejection, native draft, provider outcome, and failure events are recorded in append-only database tables.

Retention and deletion

Retention is agreed by engagement and data category. Export, return, or deletion requirements are documented in the order form or SOW before sensitive intake.

Incident response

Security reports route to the published security contact and target a same-business-day initial response during the current support window.

Continuity

The current service is principal-led. Continuity, export, deletion, support coverage, and any required backup-resource commitments must be agreed in writing.

Attestation and contract status

ItemCurrent statusBoundary
SOC 2Not completed; no certification or active audit is claimed.Future independent attestations will be evaluated against customer and contractual requirements.
ISO 27001Not completed; no certification or active audit is claimed.Future independent attestations will be evaluated against customer and contractual requirements.
FedRAMPNot completed; no authorization or active assessment is claimed.Future independent attestations will be evaluated against customer and contractual requirements.
Independent penetration testNot completed; no active test or third-party attestation is claimed.Future independent attestations will be evaluated against customer and contractual requirements.
Independent security auditNot completed; no active audit or third-party attestation is claimed.Future independent attestations will be evaluated against customer and contractual requirements.
Standard DPANot publishedAvailability and final terms must be confirmed during contracting.
Subprocessor listNot publishedEngagement-specific provider use must be confirmed before sensitive intake.
Disaster-recovery commitmentNot independently verified or contracted by defaultNo recovery objective or continuity guarantee is implied.
24x7 support / uptime SLANot included by defaultOnly applies when expressly stated in a signed agreement.

Vulnerability reports and security questionnaires: ian@pwlogicongroup.com. Do not include sensitive exploit details in an initial unencrypted message.