Security and data practices

Trust starts with labelled facts.

This staging trust center states what is true now and labels what still needs owner, security, operations, or counsel approval. It does not borrow badges, uptime promises, or legal language from a future product.

Current control matrix

Reviewed 2026-07-30 for staging accuracy.

Unknown production facts are not omitted. They are marked as approval-needed items so the next reviewer can close them deliberately.

TopicCurrent staging statementApproval needed
Hosting and infrastructureStaging website is static HTML/CSS/JS on the Pursenda staging host.Production product hosting vendors and architecture need owner/security approval.
Encryption in transitThe staging URL is served over HTTPS.Production TLS policy and certificate ownership need security approval.
Encryption at restNot publicly approved for the product yet.Storage systems, key management, and at-rest coverage need security approval.
Access and permissionsStaging site has no public login, signup, billing, or admin surface.Product authentication, sessions, roles, permissions, and audit logging need approval.
Backups and recoveryThe staging site source is kept in git.Production backup scope, restore testing, RPO, and RTO need operations approval.
Monitoring and incidentsNo uptime, response-time, or incident SLA is claimed.Monitoring, alerting, incident contact, severity definitions, and notification process need approval.
RetentionStatic website does not collect form submissions.Product retention schedule, deletion timing, and legal holds need counsel/operations approval.
Export and deletionExport and portability are named as required product commitments.Exact export formats, deletion workflow, identity verification, and timelines need approval.
Data sources and provenanceMarketing copy requires source category, identity level, freshness, confidence, and reason codes for signals.Approved production sources, geography limits, suppression/opt-out route, and model-training policy need approval.
SubprocessorsSubprocessor page exists as a staging register.Vendor list, purpose, data categories, and change-notice process need legal approval.
DPA availabilityDPA route exists as a staging review page.Final DPA terms, applicability, and signature process need counsel approval.
CertificationsNo SOC 2, ISO, HIPAA, GDPR compliance, or similar certification badge is claimed.Only current, applicable certifications may be published.

Data-practice disclosure worklist

Prospecting and intent claims need provenance.

Before public product launch, Pursenda should publish data categories, sources, purpose, identity level, update/freshness, retention, customer controls, correction/deletion route, suppression/opt-out route, geography limits, subprocessors, and whether product data trains models.

Source visibility

Every surfaced signal should carry source category, freshness, confidence, and reason code.

Identity boundary

Anonymous account activity must not be described as a named person's private search history.

Customer control

Correction, suppression, opt-out, deletion, and export routes need approved process language.

Questionnaire path

Security questionnaires can be requested by email during staging; a formal process needs approval.

Learn more

Trust documents

Legal and trust routes are public, crawlable, and staged.

Each route says what is approved versus pending so review does not hide inside the footer.

Privacy

Static-site behavior, future product data gates, contact path, and counsel review status.

Learn more

Terms

No self-serve access, no approved commercial terms yet, and owner/legal approval notes.

Learn more

Cookie policy

No analytics, trackers, pixels, embeds, chat widgets, or form cookies on this staging site.

Learn more

DPA

Data-processing addendum route and the approval items needed before customer processing.

Learn more

Subprocessors

Staging register for future vendors, purposes, data categories, and notice process.

Learn more

Acceptable use

Outreach and data-use boundaries that need approval before users send from the product.

Learn more