Trust

Built to be defensible.

An instrument of record only earns trust if every answer can be traced and every document stays where it belongs. Here is how Stature is built.

Citations at the passage

Every answer is anchored to the exact passage that produced it. A claim without a source does not ship.

Three access levels

Public, Internal, Confidential. Access is enforced at retrieval, never only hidden at display.

Encryption

TLS in transit and encryption at rest on Google Cloud. Secrets live in a managed vault, never in code.

Tenant isolation

Each workspace is schema-isolated. One organization’s record is never reachable from another.

SOC 2

Stature is not yet certified. Our SOC 2 controls are built, operating, and documented, and a SOC 2 Type I is in progress; we share our documentation, and the report when complete, under NDA.

Data handling

A short, named subprocessor list. Export and deletion on request. A Data Processing Agreement is available for organizations.

Found a vulnerability? Responsible disclosure goes to [email protected]. For a Data Processing Agreement or any other question, write to [email protected]. See our subprocessor list and privacy policy.

Read the working note Start free trial