Trust Record

Security & Trust

Built for human-reviewed knowledge capture.

DebriefCore is designed around human-reviewed knowledge, secure access, organization-level data isolation, draft-until-approved outputs, and a roadmap toward recognized security, privacy, and safety best practices.

Roadmap — not certification
DebriefCore Trust Record
Live
Status
Production
Model
Human-reviewed, draft-until-approved
Access
Authenticated workspace access
Data
Organization-scoped controls
Claims
Roadmap, not certification

Operational status

Roadmap — Not Certification

Trust summary · built toward recognized best practices, not a certification.

01Current safeguards

What is in place today.

Practical safeguards that are live in the product right now — described plainly, with no hype.

DebriefCore is built around a human-approved knowledge lifecycle. AI-generated outputs remain drafts until reviewed by authorized users, and approved knowledge can be governed with review dates, ownership, criticality, stale status, revision history, and activity logging.

Implemented

Human Review First

Every generated output stays a draft until a qualified person reviews and approves it. DebriefCore does not auto-approve outputs, certify readiness, or replace instructor judgment, mechanic authority, or official procedures.

Implemented

Organization-Level Data Isolation

Organization-scoped access controls mean each workspace can only reach its own captures, outputs, knowledge articles, and Context Packs. Row Level Security is enforced at the database layer.

Implemented

Secure Authentication

Real workspaces require authenticated access. Anonymous visitors can explore demo content, but they cannot generate real outputs or write production data.

Implemented

Draft-Only Generation Guardrails

DebriefCore organizes a debrief into structured drafts from user-provided information. By design it must not invent facts, claim official compliance, auto-approve content, or bypass human review.

Implemented

Audit Logging & Accountability

Key actions — captures, AI draft generation, human approvals, governance decisions, reference-file uploads, and data exports — are recorded in an append-only activity log. Owners and admins can review who did what, and when.

Implemented

Knowledge Lifecycle Governance

Approved knowledge does not sit unchecked. Every article carries a governance status — Current, Needs Review, Stale, Superseded, or Archived. A daily automated check marks overdue articles as stale. Every governance action writes an append-only revision entry that cannot be edited through the application UI.

Implemented

Private Reference Files

Reference photos are stored privately per organization and viewed only through short-lived signed links. They are source material for human reviewers — never sent to any AI model, and never included in data exports.

02Boundaries

Safety-critical boundaries

DebriefCore supports documentation, debriefing, training continuity, and knowledge capture. It does not replace FAA requirements, airline/operator procedures, SMS/ASAP programs, official training records, instructor judgment, mechanic authority, or qualified human decision-making.

Human decision-making remains required.
03Standards roadmap

Standards alignment roadmap

DebriefCore is being built toward recognized domestic and international security, privacy, and safety best practices. Formal compliance or certification requires future audits, policies, legal review, and security review.

Roadmap, not certification

NIST Cybersecurity Framework

Baseline

Mapped as our risk-management baseline across Govern, Identify, Protect, Detect, Respond, and Recover.

ISO/IEC 27001 readiness

Not Certified

Future information-security-management-system alignment. Not certified.

SOC 2 readiness

Not Audited

Working toward the Trust Services Criteria. Not audited.

GDPR & international privacy readiness

Needs Legal Review

Privacy controls and documentation in progress. Legal review required before any compliance claim.

OWASP web application security

Baseline

Used as the secure-development baseline for access control, injection defense, and input validation.

FAA SMS-style safety-learning alignment

Not FAA-Approved

Supports standardized debriefs and safety-learning workflows. Does not replace official systems.

Readiness disclaimer: DebriefCore is actively building against recognized security and governance baselines. Unless explicitly stated, readiness language does not mean certification, audit completion, legal compliance, or regulatory approval.

04Compliance readiness

Security & Compliance Readiness

DebriefCore maintains internal readiness documentation against major security and compliance frameworks. These are working documents — not certifications, audits, or compliance attestations.

Readiness, not certification
Mapped Baseline

NIST CSF 2.0

Mapped baseline — not NIST certified

DebriefCore's controls are mapped against the NIST Cybersecurity Framework 2.0 (Govern · Identify · Protect · Detect · Respond · Recover). Protect is strongest. Incident response and monitoring gaps are documented.

Readiness In Progress

OWASP ASVS Level 1

Readiness baseline — not formally audited

Application security controls are mapped against OWASP ASVS Level 1. Authentication, access control, and data protection controls are strong. MFA for admin accounts and standardized input validation are priority gaps.

Not Audited

SOC 2 Security

Readiness in progress — not audited

Working toward SOC 2 Trust Services Criteria (Security). Technical controls are solid; policy documentation and incident response are the critical path. Audit engagement not yet initiated.

Not Certified

ISO/IEC 27001

Readiness in progress — not certified

Building toward ISO/IEC 27001:2022 ISMS readiness. Technology controls are well-addressed. ISMS foundation — scope, risk assessment, Statement of Applicability, and formal policies — has not yet been established.

Legal Review Required

Privacy & GDPR

Documentation in progress — legal review required

Privacy documentation, data subject rights workflows, subprocessor list, and customer DPA are in progress. Independent legal review is required before any GDPR or CCPA compliance representation.

Not FAA-Approved

FAA SMS-Style Safety Learning

Safety-learning alignment — not FAA approved

DebriefCore's knowledge capture and debrief workflow aligns with safety-learning principles. It does not integrate with FAA SMS or ASAP programs, and does not substitute for any regulatory safety management requirement.

05Privacy roadmap

Data privacy roadmap

Privacy work on our roadmap. These items are not yet available — they are tracked here honestly, not implied.

  • Approved-knowledge export (JSON / CSV)Available
  • Data deletionPlanned
  • Retention controlsPlanned
  • Subprocessor listPlanned
  • Regional data considerationsPlanned
  • Multilingual privacy noticesPlanned
  • Independent legal reviewNeeds Legal Review
06Honest limits

What DebriefCore does not claim

Being clear about what we are not is part of being trustworthy. DebriefCore makes none of the following claims.

  • Not SOC 2 audited
  • Not ISO/IEC 27001 certified
  • Not GDPR legally reviewed as compliant
  • Not HIPAA-ready for PHI
  • Not FAA-approved
  • Does not replace official safety, training, or maintenance systems
  • Does not auto-approve AI-generated outputs
07FAQ

Security & Trust FAQ

Is DebriefCore SOC 2 certified?

No. DebriefCore is not SOC 2 audited or certified. We maintain internal SOC 2 readiness documentation against the AICPA Trust Services Criteria, but we have not completed a formal audit — and we will not claim a certification we do not hold.

Is DebriefCore ISO/IEC 27001 certified?

No. DebriefCore is not ISO/IEC 27001 certified. We track information-security-management-system (ISMS) readiness against ISO/IEC 27001:2022 as an internal baseline. Certification requires a formal audit by an accredited body, which we have not completed.

Is DebriefCore GDPR compliant, and can I get a DPA?

We maintain privacy and data-handling documentation, but we do not claim GDPR or CCPA compliance without independent legal review. Organizations that need a Data Processing Agreement (DPA) can request one at hello@debriefcore.com.

What security and compliance frameworks does DebriefCore follow?

DebriefCore maps its controls to recognized baselines: NIST CSF 2.0 (mapped baseline), OWASP ASVS Level 1 (readiness), SOC 2 (readiness — not audited), and ISO/IEC 27001 (readiness — not certified). These are readiness baselines that guide our security program, not certifications.

Does DebriefCore use my data to train AI models?

No. DebriefCore sends content to AI providers through their API tiers, which are not used to train the providers' public models. Reference photos are never sent to any AI model, Boardroom answers come only from your approved knowledge, and your knowledge base stays owned by your organization.

Does DebriefCore automatically approve AI-generated content?

No. DebriefCore treats AI-generated outputs as drafts. Knowledge must be reviewed and approved by an authorized human before it becomes approved organizational knowledge.

Can users see data from another organization?

No. DebriefCore is designed around organization-scoped access controls so users work inside their authorized workspace.

Can contributors edit another person's draft?

No. Contributors and members can edit their own drafts. Reviewers, admins, and owners can review and manage outputs across the organization based on their role.

Does DebriefCore track changes to knowledge?

Yes. DebriefCore supports revision history and activity logging so teams can see important changes, review actions, approvals, stale status updates, and governance events.

Does DebriefCore replace human judgment?

No. DebriefCore is built to support human judgment, not replace it. AI helps draft and structure knowledge, but authorized people review, approve, govern, and maintain it.

08Enterprise AI control

Enterprise AI Control

DebriefCore is designed so the governed knowledge workflow is not locked to a single model provider. Enterprise customers may request bring-your-own AI provider patterns — customer-owned OpenAI, Azure OpenAI, or AWS Bedrock — plus customer-owned storage/export and private-cloud deployment discussions.

Foundation in place
On request

Bring your own AI provider & key

Route AI to your own OpenAI account/key instead of the platform default. Keys are handled server-side as secret references — never stored in plaintext, never sent to the browser.

Roadmap

Azure OpenAI & AWS Bedrock routing

Run draft generation and Boardroom answers on Azure OpenAI or AWS Bedrock in your own cloud tenant/region. The provider abstraction is in place; these backends are planned, not yet live.

On request

Customer-owned storage & export

Discuss customer-owned storage and structured export of approved knowledge so your organization keeps a portable copy of its governed knowledge base.

Enterprise

Private-cloud deployment

Private-cloud / dedicated deployment patterns are available as custom enterprise engagements. Scoped per organization.

The AI provider may change. The trust model does not.

Whichever provider runs the model, DebriefCore's core trust model stays the same: AI-generated outputs remain drafts, authorized humans approve knowledge, and the organization governs that knowledge through roles, revision history, audit logs, review dates, ownership, and stale-knowledge tracking. Provider and model metadata are recorded in audit logs — never provider secrets.

Interested in a bring-your-own-AI or private-cloud configuration? Start an enterprise conversation below.

09Contact

Security questions or responsible disclosure

For security or trust questions, contact hello@debriefcore.com. Please do not send passwords, secrets, private keys, or sensitive regulated data by email.

Contact the security team