Skip to main content

Trust and evidence

Claims you can inspect. Limits you can see.

Use the source that matches your review: security posture, accessibility scope, privacy terms, live service status, release history or technical contracts.

Public evidence

Each link has a specific job. A policy, test, target and production observation are different kinds of evidence and are not presented as interchangeable.

Architecture and disclosure

Security

Read the shared-tenancy and server-side access model, then use the vulnerability disclosure policy or machine-readable security contact.

Review security

Scope and testing

Accessibility

See the WCAG target, enforced consumer surfaces, automated and manual test methods, known gaps and feedback channel.

Read the accessibility statement

Data ownership and rights

Privacy and data practices

Review the public policy for roles, purposes, retention, individual rights and the privacy contact.

Read the privacy policy

Live operational view

Service status

Open the separate public status service for current component state and published incident history.

Open service status

Repository release evidence

Release notes

Inspect generated engineering history. A release note records shipped source work; it does not prove enablement in every workspace or a production rollout by itself.

Read release notes

Generated contract

API and MCP

Inspect the generated OpenAPI artifact and the documented scoped, read-only integration boundary.

Review developer evidence

Contract and subprocessors

Data Processing Addendum

The public DPA remains disabled pending counsel review. Contact the privacy team when a signed addendum is required; a draft is not presented as an approved contract.

Contact the privacy team

Recovery: target versus evidence

Recovery objectives describe the intended operating posture. Only a completed, timed restore can establish measured recovery performance.

Documented target

A five-minute SQL recovery point objective

The current provider plan documents five-minute point-in-time recovery granularity within a two-day window. The recovery-time objective is to restore to an isolated target, validate it, and only then promote it. These are targets, not guarantees.

Latest recorded exercise

No measured end-to-end RTO yet

The September 7, 2026 Q3 exercise was blocked before data was restored. It did not attain an RTO, and independent D1 and object-storage restore receipts remain pending. KeepInTracks does not claim a successfully tested account-loss recovery from that attempt.