Application controls
- Opaque, hashed browser sessions and server-side workspace membership checks.
- Workspace-scoped database, vector retrieval, and object-storage keys.
- Private Worker and PostgreSQL networks with only SSH, HTTP, and HTTPS exposed.
- Upload extension, MIME, signature, size, rate-limit, and ownership validation.
- Provider credentials remain server-side and error responses fail closed without secret values.
Answer integrity
Generation and verification are separate operations. Unsupported or malformed output is downgraded to review or missing evidence. AI drafts are never equivalent to human approval, and only approved mapped answers reach an export copy.
Data protection gate
The durable-storage implementation requires HTTPS transport, a private bucket, explicit server-side encryption, versioning, lifecycle controls, immutable application writes, integrity checks, and permanent deletion of all retained versions. Production customer-data admission stays disabled until those controls pass against the actual provider and the AI gateway privacy review is resolved.
Limitations
TrustFill does not claim SOC 2, ISO 27001, penetration-test coverage, a DPA, a data-residency commitment, or zero retention. This page is a technical control summary, not an audit report or certification.