Security and governance

Enterprise trust starts with precise, verifiable claims.

ConsentTrace is being built for sensitive assurance workflows. This page distinguishes current foundations from active development and roadmap commitments.

No certification claims

No security certification, audit completion or compliance badge is claimed on this site. Evidence will be published only after independent verification.

Control status

A transparent view of the security programme.

Status reflects evidence available in the current repository and product foundation, not marketing aspiration.

Available

Versioned schemas

Evidence contracts can evolve predictably and submissions can be validated against a known version.

Available

Data minimisation

The product model is designed to receive consent evidence rather than broad customer production datasets.

In development

Hashed API keys

API credential storage and rotation controls are part of the active platform build.

In development

Signed webhooks

Authenticated delivery will allow consumers to verify result payload origin.

In development

Tenant isolation

Tenant boundaries are being implemented and require production verification before launch.

In development

Role-based access

Team and role controls are included in the commercial product design.

In development

Audit logs

Evidence, evaluation and review actions will be represented in an accountable history.

In development

Evidence retention controls

Configurable lifecycle controls are being designed around customer requirements.

In development

Versioned evaluation policies

Reports will identify the policy profile and version used for evaluation.

Enterprise roadmap

SSO

Enterprise identity integration is planned, with provider scope to be confirmed.

Enterprise roadmap

Private deployment

Options may be available after security, architecture and commercial discovery.

Enterprise roadmap

Custom retention

Tailored retention is planned for enterprise agreements.

Evidence responsibility

Customers control what they submit.

ConsentTrace should receive only the evidence needed for the agreed evaluation. Evidence producers remain responsible for avoiding unnecessary personal data and secrets in payloads.

Minimise

Capture only fields, observations and references required by the evidence schema.

Scope

Keep properties, regions, environments and decisions bound to the appropriate tenant context.

Retain

Apply contractual retention once configurable lifecycle controls are available.

Make evidence actionable

Discuss your security and deployment requirements early.