Trust

How the system handles your data, and the evidence behind each claim.

Trust in SigmaPointPi
/trust

Encryption, access recording, retention, backups and the practices that stand behind them. Each statement here links to what makes it true rather than asserting it.

Where something is not certified, it says so plainly. An overstated compliance claim is worse than an honest gap.

Where everything sits

Formally verified core
Formally verified core
property-based tests
property-based tests
replay harness
replay harness
Controls enforced in code today
Controls enforced in code today
Account management
Account management
Protection of audit information
Protection of audit information

How to work this page

Read what is actually held

What data exists, where, and for how long. Identifiers are encrypted at rest and appear in full only in filings that legally require them.

Check the access record

Who accessed what and when, including us. Support access is granted by you, time bounded and recorded.

Read retention

Per record type with statutory minimums. Anything eligible for disposal is listed rather than deleted silently.

Note what is not claimed

Certifications not held are stated as not held. A static check in the build fails if any surface claims one we do not have.

On a phone

Trust on iPhone 15 Pro Max

Every figure from the desktop appears here, stacked rather than reduced. Tables scroll inside themselves so the page never moves sideways, and figures keep their separators and their alignment at every width.

Questions people actually ask

Is my data used to train models?

No. Your ledger and documents are read to answer your questions and stay in your business.

What happens if I leave?

Export everything in open formats, then deletion on request within the retention period, with statutory records retained as required and stated.