Trust
What Witness does, stated plainly - not what it is certified to do.
Every claim on this page and the pages beneath it is classified as a deployed capability, a supported configuration, or planned work. Witness does not hold SOC 2, ISO 27001 or government accreditation today, and does not claim to.
Four things worth asking about before you trust a system with evidence
Governance
Access follows explicit organisation and workspace membership and role assignment, decided server-side on every request, deny-by-default. A role grants exactly the actions it is assigned - nothing is implied by name or hierarchy.
How evidence is governedSecurity
Identity, sessions, audit and encryption - what is deployed today, and what is configured but not yet enforced.
Read the security pageData & sovereignty
Where data lives, what "sovereign" actually means as a deployment profile, and what remains a supported configuration rather than a commercially proven one at scale.
Read the data & sovereignty pagePrivacy
What a participant actually consents to, per category, before anything is captured - and what happens to that consent record afterward.
Read the privacy pageWhat Witness does not currently claim
No third-party certification
No SOC 2, ISO 27001, or government security accreditation exists today. A claim of certification will only appear here once it has actually been obtained.
Database-level tenant isolation is not yet independent of the application
Tenant isolation is enforced in the repository/application layer on every request. A second, independent database-level layer (row-level security) is planned and not yet built.
API rate limiting is configured, not yet enforced
Rate-limit configuration exists in the codebase. It is not yet an enforced production control, and is not described as one.
Ask us what we did not put on this page.