Can I review your SOC 2 Type II and pentest without a sales call?+
Public artifacts (signed threat model, red-team summary, benchmark scorecards, DPA, subprocessors) are linked directly. The sensitive artifacts (SOC 2 Type II report, full pentest, and auditor/CISO acceptance letters) are released under NDA inside a scoped, expiring evidence room you can request from this page.
How are evidence packets proven, not just claimed?+
Every packet is hash-chained, KMS-signed, logged to a Sigstore transparency bundle, and re-runnable by a verifier with no access to the generating run. The packets meet an independent auditor's audit-ready bar, and the auditor acceptance letter is released in the evidence room.
Do you support SSO, SCIM, and BYOK?+
Yes — SAML SSO, SCIM provisioning, enforced MFA for privileged access, and a customer-managed-key (BYOK) option for evidence storage, alongside tenant export, retention, and deletion controls.
Are the benchmark claims independent of the artifacts?+
No — they are linked. Each superiority claim ties to a signed scorecard, and each scorecard ties to the same trust-boundary attestation in the evidence room, so the proof chain is one continuous, re-verifiable artifact set rather than separate marketing assertions.
Will you name the customer in the CISO acceptance?+
Only with written customer approval. The CISO acceptance is recorded in the evidence room with the company withheld until approved, and we never fabricate or imply a logo or quote.