Skip to main content

Compliance evidence pack

What a security review can verify about this codebase today, where the evidence lives, and — the part most vendor documentation omits — what is not covered.

The distinction that matters throughout: some of this is engineering, and some of it is certification. SOC 2 Type II, ISO 27001 and a third-party penetration test are audit activities performed on an operating organisation. No amount of code produces them, and a vendor implying otherwise is telling you something false. Everything in the first table is code and is verifiable from this repository; everything in the second is not and says so.

Verifiable from the repository​

ControlEvidenceWhere
Software bill of materialsCycloneDX SBOM generated by syft on every release and image buildrelease.yml, publish-images.yml
Artifact signingImages and release artifacts signed with cosign (keyless, OIDC)publish-images.yml
Build provenanceSLSA provenance attestation attached to each imagepublish-images.yml
Immutable audit trailprev_hash / entry_hash chain; audit rows reject UPDATE and DELETE by the app roleservices/api/app/middleware/audit_middleware.py, services/api/app/services/audit_hash.py
Credential encryption at restFernet (vault:v1) by default; per-secret DEKs wrapped by a KMS-held KEK (vault:v2) when enabledservices/api/app/security/credential_vault.py
Backup encryptionAES-256-GCM with a SHA-256 manifest; restore refuses a tampered or truncated archivescripts/backup_crypt.py, gated in integration.yml
Disaster recoverySeed, back up, drop the schema, restore, assert the row count — plus a bit-flip that must be refusedintegration.yml backup-restore job
Tenant isolationEnforced at the query layer in Postgres, ClickHouse, Neo4j, Redis, Kafka and Qdrant; offline assertions plus a live two-tenant replaytests/isolation/, isolation-live.yml
Tenant deletionErases across all five stores; the Postgres table list is discovered from information_schema so a new table cannot be missedservices/api/app/services/tenant_deletion.py
Data retentionPer-tenant policy with a purge worker; the gate asserts rows are actually deletedservices/api/app/workers/retention_purge.py
Static analysisCodeQL across Python, Go and JavaScript/TypeScript on every PRcodeql.yml
Dependency scanningDependabot alerts enabled; security_audit.py fails closed on an unscannable servicesecurity-audit.yml
Secret scanninggitleaks on every PRsecurity.yml
Container and IaC scanningTrivy, checkov, tfsecsecurity.yml
Prompt-injection resistanceThree adversarial corpora: 32 payloads scanned in isolation and 71 incident pairs whose payloads are placed in attacker-controllable fields, both against a clean twin with a recall floor and a false-positive ceiling, plus 34 held-out pairs authored after the guard was frozen and carrying no floor at all, on which the guard measures 7.1%services/agents/tests/adversarial/
Claim-to-gate traceabilityEvery product claim mapped to the CI job that fails when it stops being truedocs/audit/CLAIM_TO_GATE_MATRIX.md

The last row is the one worth reading first. It is the honest index: 290 rows GATED, 0 PARTIAL, and a ratchet that refuses to let a row sit at NO GATE. Re-read the figure from the table rather than from here — a count copied into prose goes stale in silence, which is why scripts/readme_gates.py cross-checks this sentence against the matrix.

Not covered, and not claimed​

StatusWhat it would take
SOC 2 Type IINot heldAn observation period against a named auditor, evidencing operating effectiveness of controls — an organisational activity
ISO 27001Not heldA certified ISMS, likewise organisational
Third-party penetration testNot commissionedAn engagement and a remediation cycle. CodeQL and the security workflow are static analysis, which is a different assurance
FIPS 140-3 validated cryptographyNot validatedSee FIPS posture
Customer-managed keysPartialvault:v2 wraps per-secret DEKs with a KEK in AWS KMS, so a customer-held CMK is supported for connector credentials. Backup encryption uses a static key, not a CMK
Data residency guaranteesSelf-hosted onlyThe deployment runs where you run it. No managed offering makes a residency commitment
Continuous control monitoringNot implementedThe CI gates prove the control exists in the build; nothing continuously attests a running deployment

Producing the evidence​

# Claim-to-gate summary and per-row status
python3 scripts/check_claim_gate_matrix.py

# Deployment-state snapshot, redacted and safe to attach
python3 scripts/support_bundle.py --out bundle.json

SBOMs and signatures are attached to each GitHub release; verify a signature with cosign verify against the keyless OIDC identity, and note that a signature proves the artifact came from this repository's workflow — not that the contents are free of defects.

How to read this honestly​

The controls above are real and the gates are real, and neither is a substitute for an audit. If a questionnaire asks "are you SOC 2 compliant", the answer is no. If it asks "can you evidence that credentials are encrypted at rest, that a backup restores, and that one tenant cannot read another's data", the answer is yes, and the evidence is a CI job you can read rather than a claim in a PDF.

That is a narrower claim than most vendors make and a wider one than most can show.