Security & Trust
Built for human-reviewed knowledge capture.
DebriefCore is designed around human-reviewed knowledge, secure access, organization-level data isolation, draft-until-approved outputs, and a roadmap toward recognized security, privacy, and safety best practices.
- Status
- Production
- Model
- Human-reviewed, draft-until-approved
- Access
- Authenticated workspace access
- Data
- Organization-scoped controls
- Claims
- Roadmap, not certification
Operational status
Roadmap — Not CertificationTrust summary · built toward recognized best practices, not a certification.
What is in place today.
Practical safeguards that are live in the product right now — described plainly, with no hype.
DebriefCore is built around a human-approved knowledge lifecycle. AI-generated outputs remain drafts until reviewed by authorized users, and approved knowledge can be governed with review dates, ownership, criticality, stale status, revision history, and activity logging.
Human Review First
Every generated output stays a draft until a qualified person reviews and approves it. DebriefCore does not auto-approve outputs, certify readiness, or replace instructor judgment, mechanic authority, or official procedures.
Organization-Level Data Isolation
Organization-scoped access controls mean each workspace can only reach its own captures, outputs, knowledge articles, and Context Packs. Row Level Security is enforced at the database layer.
Secure Authentication
Real workspaces require authenticated access. Anonymous visitors can explore demo content, but they cannot generate real outputs or write production data.
Draft-Only Generation Guardrails
DebriefCore organizes a debrief into structured drafts from user-provided information. By design it must not invent facts, claim official compliance, auto-approve content, or bypass human review.
Audit Logging & Accountability
Key actions — captures, AI draft generation, human approvals, governance decisions, reference-file uploads, and data exports — are recorded in an append-only activity log. Owners and admins can review who did what, and when.
Knowledge Lifecycle Governance
Approved knowledge does not sit unchecked. Every article carries a governance status — Current, Needs Review, Stale, Superseded, or Archived. A daily automated check marks overdue articles as stale. Every governance action writes an append-only revision entry that cannot be edited through the application UI.
Private Reference Files
Reference photos are stored privately per organization and viewed only through short-lived signed links. They are source material for human reviewers — never sent to any AI model, and never included in data exports.
Safety-critical boundaries
DebriefCore supports documentation, debriefing, training continuity, and knowledge capture. It does not replace FAA requirements, airline/operator procedures, SMS/ASAP programs, official training records, instructor judgment, mechanic authority, or qualified human decision-making.
Standards alignment roadmap
DebriefCore is being built toward recognized domestic and international security, privacy, and safety best practices. Formal compliance or certification requires future audits, policies, legal review, and security review.
NIST Cybersecurity Framework
Mapped as our risk-management baseline across Govern, Identify, Protect, Detect, Respond, and Recover.
ISO/IEC 27001 readiness
Future information-security-management-system alignment. Not certified.
SOC 2 readiness
Working toward the Trust Services Criteria. Not audited.
GDPR & international privacy readiness
Privacy controls and documentation in progress. Legal review required before any compliance claim.
OWASP web application security
Used as the secure-development baseline for access control, injection defense, and input validation.
FAA SMS-style safety-learning alignment
Supports standardized debriefs and safety-learning workflows. Does not replace official systems.
Readiness disclaimer: DebriefCore is actively building against recognized security and governance baselines. Unless explicitly stated, readiness language does not mean certification, audit completion, legal compliance, or regulatory approval.
Security & Compliance Readiness
DebriefCore maintains internal readiness documentation against major security and compliance frameworks. These are working documents — not certifications, audits, or compliance attestations.
NIST CSF 2.0
Mapped baseline — not NIST certified
DebriefCore's controls are mapped against the NIST Cybersecurity Framework 2.0 (Govern · Identify · Protect · Detect · Respond · Recover). Protect is strongest. Incident response and monitoring gaps are documented.
OWASP ASVS Level 1
Readiness baseline — not formally audited
Application security controls are mapped against OWASP ASVS Level 1. Authentication, access control, and data protection controls are strong. MFA for admin accounts and standardized input validation are priority gaps.
SOC 2 Security
Readiness in progress — not audited
Working toward SOC 2 Trust Services Criteria (Security). Technical controls are solid; policy documentation and incident response are the critical path. Audit engagement not yet initiated.
ISO/IEC 27001
Readiness in progress — not certified
Building toward ISO/IEC 27001:2022 ISMS readiness. Technology controls are well-addressed. ISMS foundation — scope, risk assessment, Statement of Applicability, and formal policies — has not yet been established.
Privacy & GDPR
Documentation in progress — legal review required
Privacy documentation, data subject rights workflows, subprocessor list, and customer DPA are in progress. Independent legal review is required before any GDPR or CCPA compliance representation.
FAA SMS-Style Safety Learning
Safety-learning alignment — not FAA approved
DebriefCore's knowledge capture and debrief workflow aligns with safety-learning principles. It does not integrate with FAA SMS or ASAP programs, and does not substitute for any regulatory safety management requirement.
Data privacy roadmap
Privacy work on our roadmap. These items are not yet available — they are tracked here honestly, not implied.
- Approved-knowledge export (JSON / CSV)Available
- Data deletionPlanned
- Retention controlsPlanned
- Subprocessor listPlanned
- Regional data considerationsPlanned
- Multilingual privacy noticesPlanned
- Independent legal reviewNeeds Legal Review
What DebriefCore does not claim
Being clear about what we are not is part of being trustworthy. DebriefCore makes none of the following claims.
- Not SOC 2 audited
- Not ISO/IEC 27001 certified
- Not GDPR legally reviewed as compliant
- Not HIPAA-ready for PHI
- Not FAA-approved
- Does not replace official safety, training, or maintenance systems
- Does not auto-approve AI-generated outputs
Security & Trust FAQ
Is DebriefCore SOC 2 certified?
No. DebriefCore is not SOC 2 audited or certified. We maintain internal SOC 2 readiness documentation against the AICPA Trust Services Criteria, but we have not completed a formal audit — and we will not claim a certification we do not hold.
Is DebriefCore ISO/IEC 27001 certified?
No. DebriefCore is not ISO/IEC 27001 certified. We track information-security-management-system (ISMS) readiness against ISO/IEC 27001:2022 as an internal baseline. Certification requires a formal audit by an accredited body, which we have not completed.
Is DebriefCore GDPR compliant, and can I get a DPA?
We maintain privacy and data-handling documentation, but we do not claim GDPR or CCPA compliance without independent legal review. Organizations that need a Data Processing Agreement (DPA) can request one at hello@debriefcore.com.
What security and compliance frameworks does DebriefCore follow?
DebriefCore maps its controls to recognized baselines: NIST CSF 2.0 (mapped baseline), OWASP ASVS Level 1 (readiness), SOC 2 (readiness — not audited), and ISO/IEC 27001 (readiness — not certified). These are readiness baselines that guide our security program, not certifications.
Does DebriefCore use my data to train AI models?
No. DebriefCore sends content to AI providers through their API tiers, which are not used to train the providers' public models. Reference photos are never sent to any AI model, Boardroom answers come only from your approved knowledge, and your knowledge base stays owned by your organization.
Does DebriefCore automatically approve AI-generated content?
No. DebriefCore treats AI-generated outputs as drafts. Knowledge must be reviewed and approved by an authorized human before it becomes approved organizational knowledge.
Can users see data from another organization?
No. DebriefCore is designed around organization-scoped access controls so users work inside their authorized workspace.
Can contributors edit another person's draft?
No. Contributors and members can edit their own drafts. Reviewers, admins, and owners can review and manage outputs across the organization based on their role.
Does DebriefCore track changes to knowledge?
Yes. DebriefCore supports revision history and activity logging so teams can see important changes, review actions, approvals, stale status updates, and governance events.
Does DebriefCore replace human judgment?
No. DebriefCore is built to support human judgment, not replace it. AI helps draft and structure knowledge, but authorized people review, approve, govern, and maintain it.
Enterprise AI Control
DebriefCore is designed so the governed knowledge workflow is not locked to a single model provider. Enterprise customers may request bring-your-own AI provider patterns — customer-owned OpenAI, Azure OpenAI, or AWS Bedrock — plus customer-owned storage/export and private-cloud deployment discussions.
Bring your own AI provider & key
Route AI to your own OpenAI account/key instead of the platform default. Keys are handled server-side as secret references — never stored in plaintext, never sent to the browser.
Azure OpenAI & AWS Bedrock routing
Run draft generation and Boardroom answers on Azure OpenAI or AWS Bedrock in your own cloud tenant/region. The provider abstraction is in place; these backends are planned, not yet live.
Customer-owned storage & export
Discuss customer-owned storage and structured export of approved knowledge so your organization keeps a portable copy of its governed knowledge base.
Private-cloud deployment
Private-cloud / dedicated deployment patterns are available as custom enterprise engagements. Scoped per organization.
The AI provider may change. The trust model does not.
Whichever provider runs the model, DebriefCore's core trust model stays the same: AI-generated outputs remain drafts, authorized humans approve knowledge, and the organization governs that knowledge through roles, revision history, audit logs, review dates, ownership, and stale-knowledge tracking. Provider and model metadata are recorded in audit logs — never provider secrets.
Interested in a bring-your-own-AI or private-cloud configuration? Start an enterprise conversation below.
Security questions or responsible disclosure
For security or trust questions, contact hello@debriefcore.com. Please do not send passwords, secrets, private keys, or sensitive regulated data by email.