Public controls panel · People‑first AI

Trust Center — Public Controls Panel

Public panel of the controls Data Riders publishes and keeps active for GISTM.ai and the rest of the agent portfolio. Each control listed here is auditable on request under NDA. Human accountability first; AI supports decisions — it does not replace them.

Panel status
Published
Published controls active
Encryption in transit
TLS 1.2+
on every exposed surface
Document retention
≤ 30 days
deletion after window
Foundation‑model training on your documents
No
per the commercial APIs we use

Last reviewed: 2026‑04‑27 · Next planned review: 2026‑10‑27 · Panel version: G40 · The controls below reflect what is published and running in production; evidence (CloudTrail logs, IAM configurations, sub‑processor contracts) is available under NDA via a DPA request.

Public controls panel This page lists the controls we publish and keep active in production. Each item is evidenced on request under NDA.
Published controls active
Tier 1 · Data Protection
Encryption in transit
Active

TLS 1.2+ enforced on every API endpoint and web surface. No plaintext traffic is accepted.

Encryption at rest (KMS)
Active

Managed SaaS: platform‑managed encryption at rest. Private AWS: SSE‑KMS with customer‑controlled CMKs (rotation optional). S3 Object Lock available as an opt‑in configuration for tamper‑evident evidence buckets.

30‑day document retention
Active

Uploaded documents are kept up to 30 days strictly for troubleshooting, then deleted. Only limited metadata is retained.

No foundation‑model training
Active

Your documents are not used to train foundation models — neither ours nor providers'. We distinguish: (i) foundation‑model training (forbidden, per our contracts with Bedrock, OpenAI Enterprise/ZDR and Anthropic) and (ii) tenant‑scoped continuous improvement via human feedback (only when contractually authorized and isolated per workspace). See Article 6 — Model Providers.

Tier 2 · Identity & Access
Enterprise SSO (SAML/SCIM/RBAC)
Per plan

SAML SSO, SCIM provisioning and RBAC available on Enterprise plans of our managed SaaS and on every Private‑AWS deployment. Starter/Pro SaaS plans use email+password with mandatory MFA.

MFA everywhere
Active

Multi-factor authentication enforced on all human accounts; scoped bearer tokens for machine-to-machine calls.

Least-privilege IAM
Active

Strict IAM roles with least privilege, short-lived credentials and audit logging across every pipeline.

SharePoint — Sites.Selected
Active

Microsoft Graph app-only integration scoped to Sites.Selected — granular, revocable site access, never tenant-wide.

Tier 3 · Network & Deployment
Private VPC & subnets
Active

Private-AWS deployment runs inside a customer-controlled VPC with private subnets and private networking between services.

WAF & DDoS shielding
Active

Optional AWS WAF + Shield at the edge for layer-7 filtering and DDoS mitigation on publicly exposed endpoints.

Customer cloud option
Active

Deploy GISTM.ai as pure managed SaaS, or in a private AWS account the client owns. You pick the sovereignty model.

Tier 4 · Monitoring & Response
Continuous monitoring
Active

CloudTrail, GuardDuty, AWS Config, Security Hub, Macie and Inspector — continuous logging, anomaly detection and misconfiguration alerts.

Incident response
Active

Baseline playbooks covering detection, containment (key rotation, grant revocation), recovery and transparent customer notification.

Audit trails & DPA
Active

Append‑only audit logs in CloudTrail and the application pipelines; immutable storage via S3 Object Lock (opt‑in) on Private‑AWS deployments. Public sub‑processor list and Data Processing Addendum available at /en/sub-processors/ and on request.

Named human accountability
Active

People‑first: formal client deliverables (reports, opinions, gap analyses, action plans) and security incidents have a named human owner who reviews and signs them before publication. Conversational widget outputs and exploratory iterations inside the agents are tagged as decision support — not as engineering opinions — and don't require sign‑off.

Deployment matrix Control by control: Managed SaaS · Private AWS · On‑premises (case‑by‑case).
Control Managed SaaS Private AWS (customer account) On‑premises (case‑by‑case)
SAML SSO✅ Enterprise plan✅ Standard✅ via customer IdP (ADFS/Keycloak)
SCIM provisioning✅ Enterprise✅ Optional⚠️ Manual or scoped
Granular RBAC✅ via IAM✅ via cluster IAM/RBAC
Customer‑controlled KMS keys⚠️ Platform‑managed✅ Customer CMK with rotation✅ Customer HSM/Vault
VPC / private network⚠️ Logical multi‑tenant✅ Customer‑dedicated VPC✅ Customer network
Object Lock (WORM)❌ Not available✅ Optional (S3 Object Lock)⚠️ Per customer storage
Signable DPA✅ Data Riders + SaaS provider✅ Data Riders✅ Data Riders
Sub‑processor list✅ Public✅ Reduced (only AWS + chosen model provider)✅ Minimal (only model provider, if any)
Bedrock (preferred for sensitive clients)⚠️ Per platform‑selected model✅ Recommended default (no training)✅ via VPC endpoint
CloudTrail / app logs✅ Available under NDA✅ Direct in customer account✅ Customer stack

✅ available · ⚠️ depends on plan/configuration · ❌ not available in this mode. On‑premises is evaluated case‑by‑case and requires the customer's AI stack (vLLM, Bedrock VPC endpoint or Azure OpenAI).

Data life‑cycle From original upload to deletion — every artefact has retention and a deletion rule.
Artefact Purpose Default retention Deletion rule
Original file (PDF/DOCX/XLSX)Ingestion and troubleshooting≤ 30 daysAuto‑deleted after window or immediately on contractual request
Extracted textOCR/parsing pre‑processing≤ 30 daysDeleted with the original file
Chunks (text segments)RAG indexingLifetime of the contracted projectDeleted at end of contract or on request
Embeddings (vectors)Semantic retrievalLifetime of the contracted projectDeleted with the chunks
Prompts (user queries)Request servicing≤ 30 days (Bedrock: 0‑day with ZDR; OpenAI Enterprise: ZDR)Per provider policy; ZDR opt‑in available
Generated responsesRequest servicing≤ 30 daysDeleted with the prompts
Application & audit logsForensics, compliance, troubleshooting12 months (configurable)Auto‑rotated; Object Lock optional
BackupsService continuity35‑day rollingAuto‑overwritten; encryption at rest mandatory
Metadata (filename, hash, page count)Aggregate analytics, quotas, billingContract lifetime + 24 monthsAnonymized after contract; never includes document content

Retentions can be shortened by contract. See also Privacy Policy and Sub‑processors.

Model training: what's in and what's out Foundation‑model training vs tenant‑scoped continuous improvement.
Amazon Bedrock
Preferred

Bedrock does not use prompts or responses to train foundation models, neither AWS's nor the hosted providers'. Customer logs stay in the customer's AWS account. Recommended for regulated clients. Policy: aws.amazon.com/bedrock/security-compliance.

OpenAI Enterprise / ZDR
Per plan

API and Enterprise: zero‑data‑retention (ZDR) available; no foundation‑model training on customer data. Without ZDR, retention up to 30 days for abuse detection. Policy: openai.com/policies/api-data-usage-policies.

Tenant‑scoped continuous improvement
Opt‑in

When the customer authorizes it by contract, human feedback (corrections, ratings) is used to refine prompts, RAG rules and few‑shot examples scoped to the customer's workspace. This is not foundation‑model training — it's agent configuration. The customer can revoke and export at any time.

Industry benchmarks How we aggregate without exposing client data.

Industry benchmarks published by Data Riders are built exclusively from (a) aggregated, anonymized public data (public GISTM/TSM/Copper Mark reports, ANM, ICMM, IRMA datasets) and/or (b) client data expressly authorized by contract, always anonymized at the site level before aggregation. We do not use one client's data to generate benchmarks consumed by another without written authorization. See Terms of Use, §6 — Secondary use of data.

Our 7 Guarantees The commitments Data Riders stands behind — in plain language.
See full commitments

Need a deeper look at our controls?

We share our sub-processor list, DPA and architecture diagrams with prospective enterprise clients.

Request documentation