Trust centre
Controls for financial records and the conclusions drawn from them
A procurement-review starting point. Contractual commitments and the production schedule control where they differ from this summary.
Security
- Tenant isolation is structural in the database; tenant and clearance come from the session, never the request.
- Files are accepted whole or rejected whole, financial arithmetic uses exact decimals, and every stored run names a versioned convention.
- Encryption in transit and at rest, hashed credentials and sessions, scoped grants, audit events, secret-safe logs and restore-tested migrations.
Subprocessors, including AI providers
| Provider | Purpose | Location note |
|---|---|---|
| Railway | Application hosting | United States |
| Neon / AWS | Managed PostgreSQL | Ohio, United States (us-east-2) for the current environment |
| Microsoft 365 | Operational email | US/EU service footprint |
| Stripe | Payment processing when enabled | United States/global |
| Plaid | Optional bank connection | United States |
| Cloudflare | Abuse protection and cookieless visit counts on the public pages | Global |
| Google Analytics | Public-page visit measurement, only after a visitor opts in | United States/global |
| Internal operations tooling operated by the Globixera group | Authenticates, routes and meters AI phrasing requests | United States |
| Configured AI provider | Optional phrasing of an already-calculated explanation | The exact provider/model is disclosed before enablement; customer records are not training data. |
Retention and location
Live customer data is kept for the subscription and 30 days after cancellation, then deleted; backups roll off within a further 30 days. Audit trails and published reports may be retained for seven years, and contact enquiries for two years, subject to the contract and legal holds. A customer requiring another jurisdiction must agree it before onboarding.
DPA and data protection
Transfers of personal data from the EEA, UK and Switzerland rely on the EU standard contractual clauses, with the UK addendum. The DPA is a draft for legal review and is not published. Request it, the current subprocessor schedule or a security review through the contact page, which is also the route for data-protection requests. The privacy policy lists every provider.