Trust

Trust Center

Updated June 19, 2026

Transparency, not promise. This is the public map of what is protected, what is measured, and what has not yet been independently certified.

The public contract

Privacy Policy explains information practices and rights. Terms of Service governs use. Cookie & Storage Notice inventories browser storage. Privacy Choices controls optional ecosystem continuity.

AI Disclosure explains model processing and measurement limits. Acceptable Use defines prohibited conduct. Billing, Cancellation & Refunds covers money and recurring plans. Data Requests gives one route for individual rights.

Current posture

Security: HTTPS, managed authentication, managed payments, row-level data controls, version-controlled changes, and a published vulnerability channel. See Security.

Accessibility: WCAG 2.2 Level AA is the target for public and core product flows. No independent conformance audit has been completed. See Accessibility.

Vendors: the live and feature-dependent service-provider list is published under Subprocessors.

What we do not claim

We do not currently claim SOC 2, ISO 27001, HIPAA, PCI-DSS merchant certification, independent WCAG certification, or blanket GDPR/CCPA compliance. Stripe handles card data, but using a compliant vendor does not certify the rest of this service.

Enterprise security exhibits, DPAs, service levels, data residency, regulated-data handling, and custom retention require a separate written agreement and a scope review before customer data is submitted.

Report or ask

Security reports, accessibility barriers, privacy requests, and contract questions currently reach Trent directly at trentonmcnelly@gmail.com. The channel is human; response times are not yet backed by a contractual SLA.