Trust

What Witness does, stated plainly - not what it is certified to do.

Every claim on this page and the pages beneath it is classified as a deployed capability, a supported configuration, or planned work. Witness does not hold SOC 2, ISO 27001 or government accreditation today, and does not claim to.

Four things worth asking about before you trust a system with evidence

Governance

Access follows explicit organisation and workspace membership and role assignment, decided server-side on every request, deny-by-default. A role grants exactly the actions it is assigned - nothing is implied by name or hierarchy.

How evidence is governed

Security

Identity, sessions, audit and encryption - what is deployed today, and what is configured but not yet enforced.

Read the security page

Data & sovereignty

Where data lives, what "sovereign" actually means as a deployment profile, and what remains a supported configuration rather than a commercially proven one at scale.

Read the data & sovereignty page

Privacy

What a participant actually consents to, per category, before anything is captured - and what happens to that consent record afterward.

Read the privacy page

What Witness does not currently claim

No third-party certification

No SOC 2, ISO 27001, or government security accreditation exists today. A claim of certification will only appear here once it has actually been obtained.

Database-level tenant isolation is not yet independent of the application

Tenant isolation is enforced in the repository/application layer on every request. A second, independent database-level layer (row-level security) is planned and not yet built.

API rate limiting is configured, not yet enforced

Rate-limit configuration exists in the codebase. It is not yet an enforced production control, and is not described as one.

Ask us what we did not put on this page.