Architecture and disclosure
Security
Read the shared-tenancy and server-side access model, then use the vulnerability disclosure policy or machine-readable security contact.
Review securityTrust and evidence
Use the source that matches your review: security posture, accessibility scope, privacy terms, live service status, release history or technical contracts.
Each link has a specific job. A policy, test, target and production observation are different kinds of evidence and are not presented as interchangeable.
Architecture and disclosure
Read the shared-tenancy and server-side access model, then use the vulnerability disclosure policy or machine-readable security contact.
Review securityScope and testing
See the WCAG target, enforced consumer surfaces, automated and manual test methods, known gaps and feedback channel.
Read the accessibility statementData ownership and rights
Review the public policy for roles, purposes, retention, individual rights and the privacy contact.
Read the privacy policyLive operational view
Open the separate public status service for current component state and published incident history.
Open service statusRepository release evidence
Inspect generated engineering history. A release note records shipped source work; it does not prove enablement in every workspace or a production rollout by itself.
Read release notesGenerated contract
Inspect the generated OpenAPI artifact and the documented scoped, read-only integration boundary.
Review developer evidenceContract and subprocessors
The public DPA remains disabled pending counsel review. Contact the privacy team when a signed addendum is required; a draft is not presented as an approved contract.
Contact the privacy teamRecovery objectives describe the intended operating posture. Only a completed, timed restore can establish measured recovery performance.
Documented target
The current provider plan documents five-minute point-in-time recovery granularity within a two-day window. The recovery-time objective is to restore to an isolated target, validate it, and only then promote it. These are targets, not guarantees.
Latest recorded exercise
The September 7, 2026 Q3 exercise was blocked before data was restored. It did not attain an RTO, and independent D1 and object-storage restore receipts remain pending. KeepInTracks does not claim a successfully tested account-loss recovery from that attempt.