Skip to main content

Trust Center

Security, privacy and AI governance, stated plainly.

Twelve areas. For each: what this website does in its own code, how client engagements are handled and, where nothing is published yet, a plain statement that it is not.

Where each area stands.

On this website: controls in the code that runs this site. Each one is checked against that code, so the statement cannot quietly outlive the control. In client engagements: how we design and operate client systems. These are our practices; the binding terms of any engagement are set in its agreement.

Policies and principles

What we have committed to in writing.

Security

Published statement

On this website

  • Every response carries a content security policy that forbids other sites from framing this one, HTTP Strict Transport Security, and headers that stop content-type sniffing and limit what the referrer and the browser expose.

In client engagements

  • Designed for client-controlled data environments, deployed into client cloud, private VPC or hybrid estates.
  • Least privilege applied to systems and knowledge sources, with enterprise identity integration where required.

Privacy

Published statement

On this website

  • No analytics script is requested until you agree, and declining takes one click.
  • Each enquiry is written with a redaction deadline two years after submission, which a daily sweep acts on.
  • Erasure requests are acted on directly rather than left to that deadline, and redact personal details in place so the record that the erasure happened survives.

Responsible AI

Published statement

On this website

  • The AI Readiness Diagnostic is rule-based: the same answers always produce the same recommendation, and no model is involved.

In client engagements

  • Human oversight and approval at consequential steps.
  • LLM, RAG and agent systems evaluated before release and monitored after it.
  • Answers grounded in governed sources, with escalation paths for unsafe or out-of-policy behaviour.

AI governance

Described on this page

In client engagements

  • AI systems inventoried, risk-classified and given an accountable owner, with evidence produced by the controls as they operate.
  • Governance work aligned to recognised frameworks such as ISO 42001 and the NIST AI RMF. Alignment is not certification, and we do not present it as one.

Engineering controls

How it is actually enforced.

Secure SDLC

Described on this page

On this website

  • Every change to this website is checked before it is built: linting, type checking, a JavaScript dependency audit that blocks on high-severity vulnerabilities, and an automated test that analytics cannot load without consent.
  • After each deployment, an end-to-end suite runs against the deployed site.

In client engagements

  • AI-assisted delivery governed by release gates for evaluation, security and approval.

Vulnerability management

Not yet published

On this website

  • JavaScript dependencies are audited on every change, and a high-severity finding stops the deployment.
  • Backend dependencies are pinned to exact versions, so an upgrade is a deliberate change rather than an incidental one.

Backend dependencies are not yet audited automatically, and there is no published vulnerability disclosure policy. Until there is, report a suspected vulnerability to contact@captivolt.com with “Security” in the subject line.

Access control

Described on this page

On this website

  • Administration is split into viewer, editor and admin roles, and publishing requires admin.
  • Passwords are stored as salted hashes, and repeated failed sign-ins lock the account without revealing whether it exists.
  • Viewing enquiries, diagnostic submissions or resource requests is recorded in an audit trail, as are sign-ins, failed sign-ins, account lockouts and erasures.

In client engagements

  • Access control and data classification designed into AI systems, so retrieval and agents respect the entitlements of the person asking.

Data handling

Published statement

On this website

  • The enquiry form requires only your name, work email, company and message; the area of interest is optional.

In client engagements

  • Data minimised and separated by purpose, with classification and retention treated as design decisions.

Incident response

Not yet published

In client engagements

  • Escalation paths and response playbooks for AI-related events designed into the systems we build.

No public incident notification commitment is published yet. For client engagements, notification terms are set in each agreement.

Disclosure

Subprocessors, certifications and the documents behind this page.

Subprocessors

Described on this page

In client engagements

  • Subprocessor and model-provider arrangements are agreed per engagement.
This website’s subprocessors
SubprocessorPurposeWhen it applies
Amazon Web ServicesHosting and database for this websiteAlways
Microsoft ClarityUsage analyticsOnly after you accept analytics cookies, and only while configured
Google AnalyticsUsage analyticsOnly after you accept analytics cookies, and only while configured

Certifications

None listed

No certifications are listed. One will appear here only with its issuer, scope, certificate number and validity.

  • ISO 42001 and the NIST AI RMF are frameworks our governance work aligns to. Alignment is not certification.
  • ISO 27001 and SOC 2 readiness are services we deliver to clients. They are not certifications Captivolt holds.

Policy documents

Published statement
  • Privacy Policy →

    What we collect when you use this website, why we hold it, how long we keep it, and what you can ask us to do about it.

  • Terms of Use →

    The basis on which this website is provided, and the limits of what it represents.

  • Security Statement →

    Where data runs, who can reach it, and how access, secrets, vulnerabilities, logs, incidents, AI providers and deployment are handled.

  • Responsible AI Statement →

    The principles that govern how we design and operate AI systems.

A question this page does not answer?

Ask. Where the answer depends on an engagement, it is set in that engagement’s agreement.