Trust & Security
Governed by design, evidenced on request.
ETOS GateKeeper exists because consequential decisions need traceable evidence. The same standard applies to how the platform itself handles your data.
Principles
Four commitments that shape the platform
These are architectural properties of GateKeeper, not policy statements bolted on afterwards.
Evidence stays attributable
Every determination is bound to the evidence submitted with it. Sources, timestamps and the requesting identity are recorded so an outcome can be reconstructed and reviewed later.
Authority is separated from generation
The model that reasons is not the party that approves. Authority checks and human decision points are held outside the generative path by design.
Access is granted, not self-served
Platform and agent access is provisioned after organisational review. Credentials are issued per organisation and can be withdrawn.
Gaps are declared, never filled
Where evidence is missing, GateKeeper returns INSUFFICIENT EVIDENCE rather than inference. Silent completion is treated as a failure condition.
Data handling
What we hold, where it sits, how long it stays
Plain answers to the questions enterprise assurance teams ask first.
What we hold
Account and organisation details, access-request records, assurance submissions and their evidence references, determination outputs, and billing records for purchased assurance credits.
Hosting
Application and database services are operated on managed cloud infrastructure. Region and residency requirements can be confirmed for an engagement on request before onboarding.
Transport & storage
All traffic to the platform is served over HTTPS/TLS. Integration credentials held for enterprise relays are stored encrypted and are never returned to the browser.
Access control
Application data is protected by row-level authorisation. Administrative records are reachable only through validated server-side functions and named reviewer or administrator roles.
Retention
Records are retained for the duration of the relationship and for the period needed to evidence a decision that has been relied upon. Specific retention periods are agreed per engagement.
Deletion
Deletion and export requests are handled on written request from an authorised contact at the organisation. Contact Demo@etosgatekeeper.com.
ETOS GateKeeper does not currently publish certification or audit attestations. Where a formal control assertion is required, it is addressed contractually during pilot scoping rather than claimed here.
Documentation
Available to organisations under evaluation
Data Processing Agreement
A DPA is available on request for organisations entering a pilot or enterprise engagement.
Security questionnaire
Completed responses to enterprise security and vendor-assessment questionnaires are provided during pilot scoping.
Subprocessors
The current list of subprocessors supporting hosting, database, email delivery and payment processing is provided on request and before onboarding.
Vulnerability reporting
Report suspected security issues to Demo@etosgatekeeper.com with the subject line SECURITY. We acknowledge reports and will confirm remediation status to the reporter.