TRUST / DATA PROCESSING
Named systems. Bounded use.
Last updated 5 September 2026Service providers
- Cloudflare: hosting, security, database and object storage.
- OpenAI: bounded Conductor language processing when that feature is used; server controls determine available records and tools.
- Resend: transactional access and invitation email delivery.
- Stripe: hosted checkout, invoices and payment-state events.
- Meta: authorized business asset and reporting APIs when the client shares the exact assets and permissions.
Conductor boundary
Conductor explains and drafts from permission-bound Workspace context. It may be wrong. It cannot grant access, publish a Report, move money or change a Meta asset without the corresponding server policy and required human approval. Missing Evidence remains missing; a Signal is not presented as a cause.
Security controls
Email OTP, short-lived sessions, Workspace membership, server-side roles, origin checks, rate limits, audit records, source freshness states and human publication review protect the operating boundary. Public document verification compares a verification code with the current published Report record without exposing private Report content.
Client responsibility
Clients must share only data and assets they are authorized to provide, keep user access current and avoid sensitive data outside the documented scope. A detailed processor agreement and retention schedule can be attached to the client contract.