Review without an NDA
- Security and AI-governance description
- Integration and data-flow boundaries
- Current subprocessor register
- Versioned agent evaluations
- Current service reachability
Use this index for an initial security, privacy, procurement or quality review. It separates public evidence, customer-specific documents and capabilities that are not claimed.
This public pack supports initial due diligence. The signed order, DPA and customer assurance register define the actual deployment, data and control boundary.
The agreed customer configuration may narrow this path further. A live integration or external AI interpretation is not required for the first review.
The customer names the purpose, records, fields, owner and retention period before any exchange.
Files or approved read-only sources are checked, reconciled and restricted to authorised workspace members.
Versioned rules prepare evidence and source links. External AI is optional, minimised and separately approved for each run.
A named reviewer accepts, changes or rejects the prepared result before it returns to the customer's controlled process.
Records follow the engagement schedule and authorised administrators retain a visible deletion control.
Status wording matters: “customer-specific” means the evidence depends on the agreed environment; it must not be read as universally active.
| Control area | Evidence status | What it means in plain English | Public evidence |
|---|---|---|---|
| Workspace separation | Public control description | Customer records are restricted to authorised members of the relevant workspace. | Review ↗ |
| Identity and access | Core controls implemented; enterprise setup is customer-specific | Login, roles and server checks protect access. SSO, SCIM and customer MFA enforcement are only described as active after configuration and testing. | Review ↗ |
| Data intake | Supported reference route | An agreed, fixed-scope export or approved read-only source is checked before records enter analysis. | Review ↗ |
| Retention and deletion | Agreed for each engagement | The contract states why data is held, for how long, who can request deletion and what happens to backups. | Review ↗ |
| External AI interpretation | Off unless enabled and approved for the run | Only an approved, minimised evidence package may leave the workspace for interpretation. Raw files and direct record identifiers stay out of that package. | Review ↗ |
| Agent release checks | Public versioned evaluation | Defined evaluation scenarios test evidence links, decision boundaries, limitations and repeatability. | Review ↗ |
| Service providers | Public current register | The subprocessor list names organisations that may handle data to provide the agreed service. | Review ↗ |
| Service reachability | Current status only | The status page reports whether the service can be reached now. Historical uptime is not claimed until enough measurements exist. | Review ↗ |
These explanations are deliberately practical. Contract wording and the customer's approved policies remain authoritative.
This pack is product information, not a certification, legal opinion, regulatory conclusion or guarantee. Control mappings support a buyer's review; only evidence that exists and is shareable will be supplied.
Share the intended workflow, data categories, hosting needs and questionnaire. RepeatProof will identify the applicable documents, gaps and owners before data exchange.