Enterprise

What an enterprise procurement team needs to know

This page exists so your vendor-management process can run without a call. Where a capability is not built yet, it says so — discovering that during security review is worse for both of us than reading it here.

Last updated 20 September 2026 · Protocol v9.3

Capability status, stated plainly

RequirementStatusDetail
Data processing agreementavailableSCCs with transfer impact assessment. Read the DPA.
Subprocessor transparencyavailableNamed directory with location and purpose.
Data residencyavailableDefault evidence mode keeps raw queries, rows and prompts inside your perimeter entirely.
Export & exitavailableDocumented non-proprietary schema. Run the drill before signing.
Fixed-fee contractingavailableNo success fee, no hourly billing, no consumption meter. Why that matters.
Recall / remedy SLAavailable4-hour hold, 24-business-hour notice, 5-business-day RCA. Protocol.
SAML / SCIM single sign-onnot builtIdentity is currently delegated to Werify SSO. SAML is sequenced with the first engagement that requires it.
Customer-facing RBACnot builtRole separation exists for staff; customer-configurable roles do not yet.
Exportable audit lognot builtBundle lineage is immutable and verifiable today; a general account audit log is not exposed.
SOC 2 Type IInot heldObservation window starts with the first enterprise engagement. Trust centre.
Public status pageplannedWill be hosted independently of eval.qa.

If a gap above is a blocker rather than an inconvenience, say so early — some are a sprint of work and some are a year, and we would rather tell you which.

How the commercial model is built

A fixed annual platform subscription plus a mandatory Baseline Assurance Sprint in the first four weeks. No success fee, no hourly billing, no per-query meter. The sprint is card-billed so that procurement is not on the critical path for starting work — the annual agreement can be negotiated while the first evidence is already being produced. Pricing · What the sprint covers

Governance mapping

Evidence maps to NIST AI 100-1, NIST AI 600-1 and its TEVV guidance, ISO/IEC 42001 and IEEE 1012-2024. For the EU AI Act: Regulation (EU) 2026/1744 deferred Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028, while Article 50 transparency obligations remain live from 2 August 2026. claim: external verification required We treat the deferral as an evidence-building window under Articles 9 and 15 and Annex IV, not as a reason to relax. Full standards mapping.

What we will decline

Engagements where no named Business Definition Owner exists, where we cannot read INFORMATION_SCHEMA or the dbt manifest, or where the conflict rules in the Independence Charter apply. Declines are issued in writing with the reason. A verifier that accepts every engagement is not a verifier.

Trust centre → Talk to us about procurement