Trust centre
Security claims should be as traceable as the data.
Heramind publishes the boundary between implemented controls, tested demo evidence and open production gates. This is a control programme, not an ISO certificate.
Current public production evidence covers an access-controlled demonstration with fictional data. It does not prove readiness for real client data.
01Implemented and tested for the demo
Application permissions, transaction-bound tenant context, restricted PostgreSQL runtime roles and row-level security are covered by automated tests.
- Fictional demo tenant isolated from real operator intake
- Outbound email kill switch
- Private object-storage gates and audit events
02Open before real client data
Legal and processing agreements, verified recovery evidence, enforced MFA or passkeys, mailbox security, independent penetration testing and a signed pilot scope remain gates.
03Standards direction
The control library is being mapped toward relevant ISO 27001 information-security practices, privacy obligations and secure-development evidence. Heramind is not presented as certified until an accredited certification exists.
Need the evidence behind a control?
Ask for the current trust pack and we will distinguish verified evidence from roadmap items.
Request the trust pack