MIZAN

Enterprise Trust Center

Design-partner security, data and assurance boundaries.

Open console

Accepted data

  • Public
  • Synthetic
  • Properly masked

Raw policy and action bodies are processed for the request and are not intentionally persisted. Derived governance records, hashes, risks, approvals and evidence are retained.

Identity and isolation

  • Neon Auth JWT identity
  • Database Row-Level Security
  • Credential-derived tenant
  • Tenant-bound receipts

Decision assurance

  • Deterministic ActionGate
  • Idempotency and replay controls
  • Hash-chained governance events
  • HMAC-signed evidence packs

Infrastructure

  • Vercel application hosting
  • Neon managed PostgreSQL
  • Neon Data API and Auth
  • Pre-RLS and restore-test branches

Shadow Pilot privacy

  • Source file parsed in the browser
  • Raw CSV/JSON is not uploaded by the Shadow Pilot page
  • Baseline decisions and reviewer labels remain browser-local
  • Record identifiers are SHA-256 transformed before live evaluation
  • No customer action is executed

Only the canonical safety context required for ActionGate is sent to the authenticated enterprise API. Downloaded shadow evidence can be summary-only.

Current assurance boundary

This is a design-partner pilot environment. It is not SOC 2 or ISO 27001 certification, legal advice, an independent penetration-test certification, a paid customer reference, or proof of direct superiority over paid competitors. Confidential or unmasked data requires a separately approved private deployment, DPA and security review.

Available workflows

Refund ActionGate · Privacy ActionGate · Cyber ActionGate · Masked-data Shadow Pilot

Application health