Trust Center
What you can hand your auditor.
A security review needs three things: the control list, the evidence, and who else is involved.
- Evidence pack
- PDF · CSV
- Access
- admin only
- Report contains
- counts
- Third parties
- 3
Evidence pack
Audit-day output.
For a date range you choose, a report you can put in front of an auditor is generated. Its source is the persistent audit log; the report is a read-only aggregate over it. It contains no raw personal data; only types, reason labels and counts are read. Access is limited to the admin role, and every query is scoped to your tenant.
Status
Compliance table.
| KVKK | aligned | Controls are designed in line with the data-security obligations of Turkey's KVKK. |
| GDPR | aligned | Administrative endpoints exist for portability and erasure requests. |
| ISO 27001 | aligned | The control set is mapped to ISO 27001 headings; no certification process has begun. |
| SOC 2 Type II | in-progress | In progress. We do not hold a completed audit report. |
Third parties
The only external party in the request path is the model provider.
You decide which one to use; in local-model mode none of them are involved.
| party | role | required |
|---|---|---|
| OpenAI | Model provider | optional |
| Google (Gemini) | Model provider and answer judge | optional |
| Ollama | Local model, no outbound call | optional |
Document requests and vulnerability reports
We can share the architecture document, the control list and the data processing agreement for your security review. If you have found a vulnerability, write to the same address.
security@trustlayersec.comSee it with your own data.
In a technical session we run your prompts and your policy through it live.