Jarvisby TheSEO
EN
Language · same pageNLNederlands/jarvis/vertrouwen/bewijsdossier/ENEnglish (UK)/en/jarvis/trust/security-evidence/ESEspañolnot translated yetWe do not remember your choice and never redirect you automatically.
SEC.J03 · evidence being built No certification claim
JarvisTrustSecurity evidence
SEC.J03 · security evidenceversion 0.2 · evidence being built

Not policy alone. Evidence per control.

This register turns green when design, implementation, test and owner demonstrably come together.

Security with Jarvis To the trust centreno certification claim · per control the evidence, the owner and the test frequency
FIG.01: When a row in this register turns green[##--] sheet 1/2

Four conditions at once, and only then does a control count as proven

Policy on its own says nothing. A control only counts here when all four parts are present at the same time. Below that are the eight domains from the table further down, counted by the status they hold today. Five of the eight are still waiting on a release gate.

~/jarvis/trust/security-evidence · gate[note] 5 of 8 on release gate
5release gateidentity, tenant, secrets, recovery, privacy
1design written downlogging
1interface readyAI
1to be confirmedsuppliers
# eight domains, each with the control that hangs off it and the evidence that has to be there before the status changes
DomainControlEvidence requiredStatus
IdentityMFA and least privilegeconfig export + access reviewrelease gate
Tenantserver side isolationRLS and negative testsrelease gate
Secretsseparate storage and rotationconfig + rotation testrelease gate
Loggingcritical events append-onlyschema + tamper testdesign written down
Recoverybackup and restorea recovery drill that passedrelease gate
Privacyexport and deletiontenant test + evidencerelease gate
AItool scope and approvalpolicy tests + audit eventsinterface ready
Suppliersdue diligence and contractregister + reviewto be confirmed

The domains above are our own classification. Only a valid independent certification with a scope may be communicated as certification. TheSEO holds none, in any language.

This register shows how we make our commitments demonstrable. The commitments themselves are set out in the data processing agreement, in the chapter on who may get in and how we keep it shut. If you think something is leaking, use the route on responsible disclosure.

FIG.02: Where the register stops and the word certification begins[####] sheet 2/2

Our own register proves something per control, but it proves nothing about a certificate

This is the sharpest line on the page. The classification above is our own: we picked the domains, we set the required evidence next to them and we filled in the status honestly. That is a different thing from being certified, so the word on the right is a word we do not use.

~/jarvis/trust/security-evidence · boundary[note] no certification claim
what we do doordering
Eight domains of our ownidentity, tenant, secrets, logging, recovery, privacy, AI and suppliers, chosen by us
Evidence per controleach row says which evidence turns a control green, not merely that a policy exists
Status per controlrelease gate, design written down or to be confirmed, exactly where it stands today
what we do not saywithout an audit
certifiedOnly a valid independent certification with a scope may be communicated as certification. There is none, so the word stands here struck through.
# a register of your own and a certificate are two different things; this figure puts them side by side so the difference cannot be read away
Section · Next stepreachable 24/7
Book a call