Built to be defensible.
An instrument of record only earns trust if every answer can be traced and every document stays where it belongs. Here is how Stature is built.
Citations at the passage
Every answer is anchored to the exact passage that produced it. A claim without a source does not ship.
Three access levels
Public, Internal, Confidential. Access is enforced at retrieval, never only hidden at display.
Encryption
TLS in transit and encryption at rest on Google Cloud. Secrets live in a managed vault, never in code.
Tenant isolation
Each workspace is schema-isolated. One organization’s record is never reachable from another.
SOC 2
Stature is not yet certified. Our SOC 2 controls are built, operating, and documented, and a SOC 2 Type I is in progress; we share our documentation, and the report when complete, under NDA.
Data handling
A short, named subprocessor list. Export and deletion on request. A Data Processing Agreement is available for organizations.
Found a vulnerability? Responsible disclosure goes to [email protected]. For a Data Processing Agreement or any other question, write to [email protected]. See our subprocessor list and privacy policy.