EARLY TRUST

Security and data sovereignty

The website separates implemented controls from requirements that must be closed before a pilot with real data.
01

Implemented

No server secrets in the frontend; environment configuration; reference CSP and headers.

02

Identity

Sessions, permissions and human authority are documented; central PIT identity is evolving.

03

Data

Minimization, analytics consent and separation of operational data, events and evidence.

04

Pending

MFA, production tenant isolation, backups, restore and external observability.

05

Operational truth

The interface distinguishes local, connected, degraded and human-response states.

06

Sovereignty

Each organization must retain control, export, retention and verifiable deletion.

No non-existent certification, production status or 24/7 availability is claimed.