Not policy alone. Evidence per control.
This register turns green when design, implementation, test and owner demonstrably come together.
Four conditions at once, and only then does a control count as proven
Policy on its own says nothing. A control only counts here when all four parts are present at the same time. Below that are the eight domains from the table further down, counted by the status they hold today. Five of the eight are still waiting on a release gate.
| Domain | Control | Evidence required | Status |
|---|---|---|---|
| Identity | MFA and least privilege | config export + access review | release gate |
| Tenant | server side isolation | RLS and negative tests | release gate |
| Secrets | separate storage and rotation | config + rotation test | release gate |
| Logging | critical events append-only | schema + tamper test | design written down |
| Recovery | backup and restore | a recovery drill that passed | release gate |
| Privacy | export and deletion | tenant test + evidence | release gate |
| AI | tool scope and approval | policy tests + audit events | interface ready |
| Suppliers | due diligence and contract | register + review | to be confirmed |
The domains above are our own classification. Only a valid independent certification with a scope may be communicated as certification. TheSEO holds none, in any language.
This register shows how we make our commitments demonstrable. The commitments themselves are set out in the data processing agreement, in the chapter on who may get in and how we keep it shut. If you think something is leaking, use the route on responsible disclosure.
Our own register proves something per control, but it proves nothing about a certificate
This is the sharpest line on the page. The classification above is our own: we picked the domains, we set the required evidence next to them and we filled in the status honestly. That is a different thing from being certified, so the word on the right is a word we do not use.
