Skip to main content
← Back to website
TRUST CENTRE

Security, resilience and AI governance

Last updated 30 August 2026

RepeatProof is an intelligence layer—not a replacement for a controlled quality system or professional judgement. This page describes implemented product controls and the evidence we can provide. It does not imply a certification, legal conclusion or control that has not been configured for a specific customer.

Architecture and customer boundary

  • Separated workspaces: tenant membership and row-level database policies restrict customer records to authorised workspace members.
  • Customer-controlled option: a customer may retain records in its own approved data plane and run outbound, read-only connectors in its environment.
  • Least data: pilots begin with a bounded historical export or agreed read-only source. Credentials stay in the deployment secret manager, not connector records.
  • Authoritative system: the customer's QMS and named people remain authoritative for root cause, disposition, release, conformity and closure.

Identity and access

Supabase authentication, tenant roles and server-side entitlement checks protect the application. Each customer Assurance register records MFA policy and enforcement, SSO protocol and state, SCIM state, verified domains and session target. Enterprise identity is shown as “not configured” until the relevant provider is tested and activated; the public website does not claim universal SSO or SCIM deployment.

Data protection and lifecycle

  • Transit and storage: production providers are required to protect data in transit and at rest; exact region, provider and customer-controlled key boundary are agreed for the engagement.
  • Residency: the configured hosting region is recorded per workspace. Marketing wording does not override the contracted location.
  • Retention and deletion: purpose, fields, retention window, deletion instruction and backup boundary are agreed before exchange. Customer administrators retain an auditable deletion control.
  • Backups: owner, recovery-point target, recovery-time target and restore-test evidence are recorded per customer rather than inferred from a generic platform claim.

AI and model governance

External AI interpretation is off unless both the engagement control and an authorised user approve the individual run. Only a minimised calculated-evidence package is sent; raw files and direct record identifiers remain in the customer workspace. Engine, prompt and benchmark versions are recorded. CAPA, Inspection and Audit releases are blocked by evidence-traceability, decision-boundary, confidence/limitations and deterministic-repeat checks. See the versioned evaluation record.

Secure delivery and monitoring

Changes pass locked dependency installation, unit and agent-benchmark tests, a production build, controlled browser journeys and accessibility checks on Node 22. Production promotion is a separate protected action that deploys the verified prebuilt artifact. Application failures carry request identifiers and structured server logs; current reachability is shown on the service status page. Historical availability is not claimed until measurement history exists.

Incident response and resilience

Customers can report issues directly through Sentinel in the secure workspace. The response process preserves deployment, request and audit evidence; assigns severity and an accountable lead; and records containment, recovery, communications and corrective actions. Customer-specific incident contacts and recovery targets are visible in Workspace Setup → Assurance.

Standards and regulatory mapping

The due-diligence pack maps relevant controls to OWASP ASVS, NIST AI RMF, ISO/IEC 42001 concepts, EU AI Act governance themes and WCAG 2.2 AA criteria. These mappings support assessment and gap review; they are not certificates or legal advice. Any certification or formal conformity statement must come from the relevant accredited body or qualified adviser.

Subprocessors and integrations

The current provider register is maintained on the subprocessors page. The integration catalogue distinguishes supported reference adapters from customer-specific discovery. No unverified vendor certification is implied.

Due-diligence pack

Prospective customers can request the data-processing agreement, architecture and data-flow summary, role/access matrix, retention/deletion schedule, model-processing description, release and incident runbooks, current subprocessor list and security questionnaire response. External penetration-test or certification evidence is supplied only when it exists and its sharing terms permit it.

Request a scoped assurance review or contact the RepeatProof security team.

Responsible disclosure

Report a suspected vulnerability privately through the RepeatProof security team. Include enough detail to reproduce the issue and do not access data that is not yours.