Trust Center
Security, data, and AI operating boundaries
Public practices, limitations, and document-request paths are visible without implying certification, audit, authorization, or universal compliance.
Trust CenterPublic operating boundaries
- Purpose
- Review public security, data, AI-authority, accessibility, continuity, and document-request practices.
- Boundary
- Certification, audit, authorization, insurance, procurement status, and universal compliance are not implied.
Public operating approach
Security overview
The public site remains static-first for public content, uses local assets and local search, and does not configure external analytics or a third-party lead platform. An optional first-party endpoint stores only consented, public-safe inquiry data in a separately installed private application; sensitive technical material remains prohibited. Client security requirements are qualified and scoped before access.
- Least authority and role separation
- Secure credential handling through approved client channels
- Version control, review gates, logging, and rollback where scoped
- Environment and data-boundary separation
- Data minimization and dependency review
- No secrets committed to public source or client-side code
- Private lead configuration, keys, application logic, and database access remain outside the public document root
- Lead content is encrypted at rest and can be cryptographically redacted when the private application is installed
Public classification guide
Data-handling boundaries
Public channels are limited to public-safe qualification. Confidential or regulated evidence moves only after responsibility, scope, contractual terms, and an approved transfer method are clear.
- Public-safe: organization, role, public notice links, high-level system context, timing, and budget range
- Confidential business information: accepted only through an approved private channel after qualification
- Regulated or sensitive information: requires explicit contractual and technical handling decisions
- Prohibited through public forms and email: credentials, private source code, customer records, PHI, financial account data, classified, CUI, export-controlled, source-selection-sensitive, or privileged material
Operating boundary
AI use and human authority
AI output is treated as proposed work. Consequential action requires explicit human authority, and generated claims require source support or an unknown state.
- Client data is not placed in unapproved tools
- Data, retention, and model-use boundaries are defined for the engagement
- Human review remains explicit for consequential work
- AI use is disclosed when materially relevant
- Unknowns are not converted into certainty
- Approval and execution are separated where risk warrants
Engineering practice
Secure software practices
Engagements may use secure-development concepts appropriate to the system, including least authority, reviewable change, dependency management, versioned evidence, test gates, rollback, and explicit operational ownership.
- Source and change control
- Dependency and configuration review
- Secrets excluded from source
- Review and release gates
- Logging, observability, and rollback design
- Client-owned artifact export and handoff
Delivery principle
Business continuity and exit
The delivery model favors client-owned artifacts, exportable formats, documented dependencies, knowledge transfer, and a planned handoff rather than manufactured lock-in.
- Client retains client-specific deliverables
- Pre-existing methods and templates remain provider IP
- Dependencies and external services are documented
- Decision and risk records are exportable
- Handoff and exit expectations are named in scope
- Additional personnel are disclosed and scoped
Buyer-operable assurance path
Trust document catalog
Start with public material, then request only the engagement-specific evidence needed for the decision. Access status is explicit so a request does not imply that an audit, certificate, report, or prebuilt response exists.
| Item | Access | Helps answer | Boundary | Action |
|---|---|---|---|---|
| Security overview | Public | What public security and delivery practices are currently described? | A public operating overview, not an audit, certification, penetration test, or security guarantee. | Download PDF |
| Public data, AI, privacy, accessibility, and continuity boundaries | Public | What can be reviewed before sharing confidential or regulated information? | Public statements describe current practices and limits; they do not establish universal compliance. | Review boundaries |
| Security or customer-assurance questionnaire response | Requestable | Can LongTermCapabilities answer the questions relevant to a specific procurement or engagement? | Responses are scoped to the actual service, tools, data, responsibilities, and available evidence; no blanket attestation is implied. | Prepare request |
| Engagement data-flow and handling boundary | Requestable | Which data, environments, tools, people, transfers, retention rules, and exclusions apply to the proposed work? | The useful answer depends on a bounded engagement and client requirements; sensitive detail moves through an approved channel. | Prepare request |
| AI use and human-authority walkthrough | Requestable | Where may AI assist, who reviews it, and who retains authority over consequential action? | The walkthrough describes the proposed engagement and does not certify the buyer's broader AI program. | Prepare request |
| Secure delivery, continuity, and exit response | Requestable | How will change, access, evidence, handoff, continuity, and exit be handled for the workstream? | Controls and artifacts are selected for the scoped work; no 24/7 operations or universal recovery guarantee is implied. | Prepare request |
| Engagement-specific tool, dependency, and subprocessor disclosure | After scope | Which third-party tools or services would actually be used for the proposed engagement? | No universal list is asserted before scope. The applicable set is disclosed and approved for the engagement. | Prepare request |
| Independent assurance reports and certifications | Not asserted | Is an independent audit, SOC report, ISO certificate, penetration-test report, or comparable assurance artifact publicly claimed? | No such artifact is publicly asserted as currently held. Unknown or unavailable evidence is not presented as complete. | No public artifact claimed |
Disclosure status
| Disclosure | Status | Public statement | Reviewed |
|---|---|---|---|
| Public-site architecture | Public | Static-first public content, local assets, local search, optional first-party public-safe lead intake, and no configured advertising pixels, external analytics, hosted search, external fonts, third-party lead platform, public chatbot, or live MCP transport. | 2026-07-24 |
| Data-handling boundaries | Public | Public forms and public email are limited to public-safe qualification. Confidential or regulated evidence requires an approved channel after scope and responsibility are clear. | 2026-07-24 |
| AI use and human authority | Public | AI output is proposed work. Consequential actions require explicit authority, source support, review, and blocked-action criteria appropriate to the engagement. | 2026-07-24 |
| Secure software practices | Conditional | Engagement controls are selected for the system and may include least authority, version control, dependency review, test and release gates, rollback, environment separation, and secret exclusion. | 2026-07-24 |
| Framework alignment | Public | The practice can map technical work to public frameworks for readiness and evidence discussions. Certification, attestation, approval, and universal compliance are not asserted. | 2026-07-24 |
| Procurement and insurance status | Private on request | Verified entity, registration, insurance, and legal documents are shared through an approved procurement channel when relevant. Unverified values are not displayed. | 2026-07-24 |
Document request process
Use the catalog to identify the smallest relevant request. Public documents are available directly; engagement-specific material is qualified before private exchange.
- Legal entity details
- W-9
- Insurance certificates
- Registration records
- Security materials
- Standard agreements
- Other opportunity-specific vendor documents
Next action
Ask for the evidence appropriate to the decision.
A public page is not a substitute for due diligence, and private materials are not sent before fit and handling are established.
Prefer a direct conversation? Call 1 (464) 274-1476