datum

Trust Center

Everything a security review needs. Nothing it has to take on faith.

datum is the evidence-controlled case workspace for construction claims and arbitration. This page is the single place for our security documentation, subprocessors and compliance posture - with every item marked live, documented, or roadmap. We never publish a claim we cannot evidence; it is the same discipline the product enforces on claims.

Posture at a glance

Encryption Live

TLS in transit; AES-256 at rest via managed keys; encrypted, restore-verified backups.

No AI training on client data Live

Contractual and architectural. Org-scoped learning only; nothing crosses tenants.

Isolation & audit Live

Per-organisation row-level security at the database; append-only audit log on every human override and deletion.

GDPR & UAE PDPL Documented

Control-by-control posture in the launch compliance checklist; UAE counsel sign-off is a launch gate.

SOC 2 / ISO 27001 Roadmap

Certification is a funded post-revenue milestone. We publish the honest state instead of a claim.

Documentation

Request any document.

Shared by email, under NDA where appropriate. Drafts are labelled as drafts - you will never receive a document presented as more final than it is.

Core policies
Information Security PolicyRequest access
Access Control PolicyRequest access
Encryption PolicyRequest access
Data Classification & Retention PolicyRequest access
Acceptable Use PolicyRequest access
Backup & Restore PolicyRequest access
Logging & Monitoring PolicyRequest access
Vulnerability & Patch Management PolicyRequest access
Change Management PolicyRequest access
AI governance
AI Security & Risk PolicyRequest access
AI Impact AssessmentRequest access
Data Boundaries & LearningRequest access
Model Provider Terms (Anthropic - no training, ZDR) · summaryRequest access
Resilience & response
Incident Response PlanRequest access
Business Continuity & DR PlanRequest access
Risk Register & ManagementRequest access
Certified Deletion Procedure & Sample CertificateRequest access
Compliance & commercial
UAE Launch Compliance Checklist (PDPL / DIFC)Request access
Security Questionnaire - Standard AnswersRequest access
Vendor & Subprocessor RegisterRequest access
Privacy Policy · draft - counsel reviewRequest access
Terms of Service · draft - counsel reviewRequest access
Subprocessors

Seven vendors. Stated plainly.

Every service that touches any datum data, what it does, where it runs, and what it can see. Changes to this list are notified to clients in advance.

VendorRoleRegionData exposure
AnthropicLLM inference (extraction, drafting, verification)USCase text at inference time only; no training on API data; zero-data-retention terms on enterprise tier
Fly.ioApplication compute, database, queueEU (Frankfurt) - me-central-1 planned pre-clientCase records and derived data, per-org isolated
Tigris DataObject storageCo-located with computeDocument originals and page images, encrypted at rest
VercelWebsite hosting and DNSGlobal edgeNo case records; public site and workspace UI shell only
ClerkAuthenticationUSSign-in identities (name, email); no case records
Microsoft 365Business emailEU/UAE per tenantBusiness correspondence; no case records by policy
GitHubSource code hostingUSCode only; never client data

Running a vendor review? Send the questionnaire as-is - our standard answers document covers the common frameworks, and anything it does not cover gets a written answer within two business days.

Start a security review