HeramindBook a Cash Diagnostic
Trust centre

Security claims should be as traceable as the data.

Heramind publishes the boundary between implemented controls, tested demo evidence and open production gates. This is a control programme, not an ISO certificate.

Current public production evidence covers an access-controlled demonstration with fictional data. It does not prove readiness for real client data.

01

Implemented and tested for the demo

Application permissions, transaction-bound tenant context, restricted PostgreSQL runtime roles and row-level security are covered by automated tests.

  • Fictional demo tenant isolated from real operator intake
  • Outbound email kill switch
  • Private object-storage gates and audit events
02

Open before real client data

Legal and processing agreements, verified recovery evidence, enforced MFA or passkeys, mailbox security, independent penetration testing and a signed pilot scope remain gates.

03

Standards direction

The control library is being mapped toward relevant ISO 27001 information-security practices, privacy obligations and secure-development evidence. Heramind is not presented as certified until an accredited certification exists.

Need the evidence behind a control?

Ask for the current trust pack and we will distinguish verified evidence from roadmap items.

Request the trust pack