Trust

Security

This page describes how the Trust Desk actually works today. It deliberately avoids claims we cannot evidence.

Workspace isolation

Every document, extracted passage, vector, review and question is stored with the workspace it belongs to. Database row-level policies scope every read and write to the workspaces you are a member of, and they are applied by the database itself rather than by the interface. A request for another workspace's record returns nothing, not a rejected page.

Evidence files

Uploaded files are stored in a private bucket that has no public URL. Downloads are served through short-lived signed links that expire after 60 seconds and are only minted after your membership of that workspace has been confirmed. Uploads are checked for extension, declared type, size and file signature before anything is read.

Uploaded content is never an instruction

Text extracted from your documents is passed to the language model inside a fenced, clearly labelled data block, below fixed system rules. Instruction-shaped passages are neutralised, and any draft that echoes system instructions is rejected and marked for human review instead of being shown as an answer.

Human approval

A response can only be marked approved when the database itself agrees: approved and in-scope evidence exists, no authoritative sources contradict each other, the draft is non-empty and grounded, and a named person approved it. Those checks run in database triggers, so they hold even if a request bypasses the interface.

Logging

Operational logs record the request identifier, workspace, operation, duration, outcome and failure category. Credentials, tokens, passwords and document contents are never written to logs.

Deletion

A workspace owner can delete all customer content — files, extracted text, vectors, reviews and answers. The workspace record, the audit history and a record of the deletion itself are retained so the deletion remains provable.

What we do not claim

The Trust Desk does not hold a SOC 2 report, an ISO/IEC 27001 or 42001 certificate, a HIPAA attestation, PCI DSS validation or a FedRAMP authorization, and it does not claim an independently audited security programme. It also does not claim a zero-retention agreement with model providers unless your workspace settings record one as verified. Where a buyer needs one of those, tell them the honest current position.

Reporting a vulnerability

Email security@quadruplelabs.uk with a description and reproduction steps. We aim to acknowledge within two working days. Please do not test against another customer's workspace.

Back to homePrivacy and AI processing