Current decision

88% ready, external proof still required

Code and customer-facing trust surfaces are strong. Final enterprise confidence still requires a real tenant access review, independent pentest and measured production hardening evidence.

4

trust lanes

6

acceptance checks

4

external proofs

Enterprise proof lanes

What needs to be true before we sell trust hard

Access and permissions

Tenant admins can explain users, roles, review actions and sensitive access without exposing internal operator tools.

  • role inventory
  • access review
  • least privilege
  • tenant isolation

Audit and evidence

Security center, trust center, compliance pack and release evidence give customers a clear proof trail.

  • audit log
  • control evidence
  • release proof
  • owner trace

Data governance

Export, retention, delete and incident explanations are visible as customer-safe trust surfaces.

  • export/delete
  • retention policy
  • DPA pack
  • incident history

Public attack surface

Public probes cover sensitive Flow endpoints, CORS, method rejection, malformed inputs and secret leakage.

  • public data guard
  • CORS/origin
  • security headers
  • secret leakage

Acceptance

Go-live trust checks

  • A customer can understand what security controls exist and where proof lives.
  • Tenant access review has owner, action, status and evidence.
  • Export, retention and delete paths are visible without exposing internal-only mechanics.
  • Public status/trust copy does not overclaim uptime or external certification.
  • Security review findings are tracked to closure.
  • Independent pentest is required before final enterprise claim.

External proof

Not a code blocker, but still a sales blocker

  • Run one real tenant access review with customer-approved evidence.
  • Complete independent external penetration test.
  • Archive measured CSP rollout evidence after production observation.
  • Attach signed DPA/compliance pack for first enterprise customer.