Skip to main content
5PLACES
LEFT
FOUNDING MANUFACTURER PROGRAMMEProof Sprint · £2,950–£4,500
BUYER ASSURANCE PACK

Security evidence.
Without inflated claims.

Use this index for an initial security, privacy, procurement or quality review. It separates public evidence, customer-specific documents and capabilities that are not claimed.

PACK STATUSPublic assurance summaryLAST REVIEWED5 September 2026QMS STATUSCustomer-authoritativeCERTIFICATIONNone implied
EVIDENCE STATUS

Know what you can review
before sharing data.

This public pack supports initial due diligence. The signed order, DPA and customer assurance register define the actual deployment, data and control boundary.

PUBLIC NOW

Review without an NDA

  • Security and AI-governance description
  • Integration and data-flow boundaries
  • Current subprocessor register
  • Versioned agent evaluations
  • Current service reachability
CUSTOMER-SPECIFIC

Prepared after scope is known

  • Data-flow and architecture boundary
  • Role and access matrix
  • Retention, deletion and backup schedule
  • DPA and customer subprocessor schedule
  • Questionnaire response and incident contacts
NOT CLAIMED

Evidence is never assumed

  • Universal SSO, SCIM or MFA enforcement
  • Unconfigured residency or recovery targets
  • Unheld certification or audit reports
  • Unperformed penetration-test results
  • Customer outcomes without approval
PROCESSING PATH

The data journey
in plain English.

The agreed customer configuration may narrow this path further. A live integration or external AI interpretation is not required for the first review.

01

Agree the minimum dataset

The customer names the purpose, records, fields, owner and retention period before any exchange.

02

Validate and isolate

Files or approved read-only sources are checked, reconciled and restricted to authorised workspace members.

03

Calculate before interpreting

Versioned rules prepare evidence and source links. External AI is optional, minimised and separately approved for each run.

04

Human review and controlled handback

A named reviewer accepts, changes or rejects the prepared result before it returns to the customer's controlled process.

05

Retain or delete as agreed

Records follow the engagement schedule and authorised administrators retain a visible deletion control.

CONTROL INDEX

Technical control.
Practical meaning.

Status wording matters: “customer-specific” means the evidence depends on the agreed environment; it must not be read as universally active.

Control areaEvidence statusWhat it means in plain EnglishPublic evidence
Workspace separationPublic control descriptionCustomer records are restricted to authorised members of the relevant workspace.Review ↗
Identity and accessCore controls implemented; enterprise setup is customer-specificLogin, roles and server checks protect access. SSO, SCIM and customer MFA enforcement are only described as active after configuration and testing.Review ↗
Data intakeSupported reference routeAn agreed, fixed-scope export or approved read-only source is checked before records enter analysis.Review ↗
Retention and deletionAgreed for each engagementThe contract states why data is held, for how long, who can request deletion and what happens to backups.Review ↗
External AI interpretationOff unless enabled and approved for the runOnly an approved, minimised evidence package may leave the workspace for interpretation. Raw files and direct record identifiers stay out of that package.Review ↗
Agent release checksPublic versioned evaluationDefined evaluation scenarios test evidence links, decision boundaries, limitations and repeatability.Review ↗
Service providersPublic current registerThe subprocessor list names organisations that may handle data to provide the agreed service.Review ↗
Service reachabilityCurrent status onlyThe status page reports whether the service can be reached now. Historical uptime is not claimed until enough measurements exist.Review ↗
PLAIN-ENGLISH GLOSSARY

Common terms.
No decoding required.

These explanations are deliberately practical. Contract wording and the customer's approved policies remain authoritative.

Tenant isolation
Separating each customer’s records and checking membership before the application returns them.
Row-level security
Database rules that decide which individual records a signed-in user is allowed to read or change.
Least privilege
Giving a person or system only the access needed for the agreed task, and no more.
MFA
A second sign-in check in addition to a password. Customer enforcement is confirmed during setup.
SSO
Using an organisation’s identity provider to sign in. It is customer-specific and is not claimed as active until configured and tested.
SCIM
Automated user-account creation and removal from an organisation’s identity system. It is optional and configuration-dependent.
Data residency
The country or region in which the agreed service stores or processes customer data. The contracted configuration is authoritative.
DPA
The data-processing agreement: the contract that sets out processing roles, instructions, safeguards and relevant service providers.
Subprocessor
Another organisation used to deliver part of the service that may process relevant data under contract.
RPO / RTO
The agreed recovery point and recovery time: how much recent data could be lost and how quickly service is intended to recover. Targets are customer-specific.
Important limitation

This pack is product information, not a certification, legal opinion, regulatory conclusion or guarantee. Control mappings support a buyer's review; only evidence that exists and is shareable will be supplied.

Need the customer-specific
due-diligence set?

Share the intended workflow, data categories, hosting needs and questionnaire. RepeatProof will identify the applicable documents, gaps and owners before data exchange.

Request an assurance review