Skip to content

Trust center

Don’t take our word for it. Watch us prove it.

Everything on this page is measured the moment you open it — real database reads, real access-control attempts, real response times. Press the button and watch the platform answer.

All checks passing
Checks passing
4/4
Average response
158 ms
Last verified
03:27:40 PM

Live verification

Four checks, run against production — right now.

Nothing here is a mock-up or a screenshot. Each check reaches the live platform, and the number beside it is how long that request actually took.

Last measured 10/4/2026, 3:27:40 PM

Application database

78 ms

Reads a live published record straight from the production datastore.

Record returned from the datastore

Privileged endpoint

312 ms

Asks a restricted, staff-only endpoint for its records with no credentials attached.

Refused without credentials (HTTP 401)

Public form validation

105 ms

Sends a deliberately malformed inquiry to the live intake endpoint and confirms it is turned away.

Malformed submission rejected (HTTP 400)

Public site delivery

138 ms

Requests the public site from outside the browser and times the response.

Served over HTTPS (HTTP 200)

Verification history

A record that builds itself, one visit at a time.

100%

Fully operational

6

Verifications

Each bar is one verification run recorded by the platform itself, kept for the most recent 60 runs. The strip fills in as the page is visited, and it is written only by the server.

Controls in place

What is actually switched on — not what sounds good.

Each of these is implemented in the platform you are using right now, and the four checks above are how we prove it.

Deny-by-default records

Sensitive collections — leads, applications, audit entries, files — deny all direct access. Only vetted server logic may touch them.

Server-side authorization

Every privileged operation re-checks the caller’s identity and role on the server. The interface is never the lock.

Audit trail

Administrative changes to projects, files, outreach, users, and hiring are written to a reviewable audit log.

Rate limiting

Public intake is throttled per address, so a form cannot be used to flood the system.

Spam and bot guards

Public forms carry hidden honeypot fields and turn away anything that trips them — quietly, with no hints.

Private file storage

Client uploads are stored privately and handed out only through short-lived signed links.

No private data in public metadata

Protected routes stay out of the sitemap, and no record data reaches page titles or structured data.

Validated input

Every public payload is bounded, typed, and checked before it reaches a stored record.

Our honest fine print

This page shows what we can prove — and nothing else.

These checks cover this platform’s database, access control, input validation, and delivery. They are not a certification, an uptime guarantee, or a claim about systems outside it. Anything we cannot measure, we do not print.

Want the full picture?

Ask us how your organization’s data is protected — we will walk through it with you, including what we do not claim.

We use optional analytics to understand how this website is used. No analytics loads until you allow it, and declining keeps everything on the site working.