How your evidence is handled
These are intended deployment requirements to be agreed with each client. They are not an implemented certification or a security audit.
- 01
Canonical identity
One agreed client, programme and cohort identity used by every product.
- 02
Agreed access
Who sees what is agreed with the client before deployment.
- 03
Raw · derived · reviewed
Kept separate so any finding can be traced back and challenged.
- 04
Review and challenge
Humans approve interpretations; challenges are appended, never overwrite.
- 05
Logging
Actions on evidence are recorded.
- 06
Controlled environments
Test and production are separated; test data cannot reach production.
- 07
Backup and recovery
Agreed recovery arrangements as part of deployment.
- 08
Retention, export, offboarding
Agreed retention periods and a defined exit route for client data.
Local bridge simulator: Pulse → Insight
Operates only on six fake local events. It does not contact live Pulse or Insight, and shows behaviour we intend to build, not a production health signal.
Demo audit history
No demo actions yet.