Security and buyer assurance

Inspect the controls, boundaries and evidence.

PolicyOps is designed around tenant-scoped access, source provenance, human accountability and auditable activity. Deployment-specific claims still require evidence from the environment being procured.

Last reviewed 24 July 2026 · Buyer assurance guide · No certification claim

Assurance model

Separate product controls from deployment proof.

Security review is strongest when a buyer can distinguish three things: what the product is designed to enforce, what has been tested in the repository, and what is demonstrably configured in the environment they will use.

PolicyOps includes role and workspace controls, evidence provenance, upload validation, audit context and optional AI-provider boundaries. A procurement review should still verify live identity configuration, database protections, retention, backup, monitoring, incident response and provider terms.

Control areas

What a buyer should inspect.

01

Tenant and role boundaries

Protected routes resolve organisation and workspace context, apply permissions and deny cross-workspace access. Live identity mapping remains deployment evidence.

02

Source and upload safety

Policy sources retain provenance. Upload controls restrict supported files and size, while production malware scanning and retention controls remain environment requirements.

03

Audit and integrity context

New records can carry deterministic integrity markers and protected database ledgers where migrations are deployed. This is tamper evidence, not a legal-grade immutability claim.

04

Optional AI boundaries

Core workflows remain available without AI. Smart Search and Intelligence depend on entitlement, provider readiness and the agreed processing configuration.

Procurement checklist

Request evidence at the right level.

The appropriate assurance pack depends on the hosting model, data classification and proposed use. A local demonstration can validate a workflow, but it does not prove a production control is operating.

  • How are identity, MFA, sessions and role changes configured?
  • Which data is stored, where, and for how long?
  • How are backups restored and recovery tested?
  • Which model provider receives data, and under what terms?
  • How are uploads scanned, quarantined, deleted and exported?
  • Which logs and alerts are monitored operationally?

Buyer questions

Clear answers without certification theatre.

How is tenant access enforced?

Protected API routes resolve organisation and workspace context, apply role permissions and deny cross-workspace access. Production deployments should also verify current identity-provider mapping and database guardrail migrations.

What does audit tamper evidence mean?

New events can carry deterministic SHA-256 markers and local chains; database migrations reject mutation of protected ledgers where deployed. This is not external WORM storage or a claim of legal-grade immutability.

Can AI be disabled or privately configured?

Yes. Core PolicyOps remains available without AI. Hosted, customer-provided, private or local model choices require deployment configuration, provider terms and operational verification.

What still needs customer-specific assurance?

Identity configuration, data residency, retention, backup and restore, monitoring, connector permissions, incident response, model-provider terms and any claimed certification must be evidenced for the deployed environment.

Does PolicyOps train models on customer policies?

PolicyOps does not require model training on customer policies. Provider processing, logging, retention and training terms depend on the configured deployment and must be confirmed contractually.

Is PolicyOps ISO 27001 or SOC 2 certified?

No certification claim is made on this page. Buyers should review current organisational certification and deployment evidence during procurement.

Assurance boundary

Repository capability is not deployed proof.

PolicyOps can provide product controls and an evidence route. Buyers and suppliers must still verify the live environment, operational ownership and contractual position before relying on a security or compliance claim.