Security

Evidence should reveal what is necessary not everything you know.

Evidence is processed in AffectLog's hosted service, in your organisation's isolated workspace. There is no customer-hosted runner today. AffectLog records documents, summaries and results about the system - not the raw records it processes - and every decision taken on them.

Evidence, not data

Documents, summaries, and results - never the raw records.

Hash-linked decisions

Every clearance decision is written to an append-only, hash-linked log

Role-bound review

Server-side checks; no one reviews what they cannot defend

Everything expires

Passports and visas expire by default - renewal is a new decision

Security principles

Eight controls. On by default. Not configurable off.

Raw export is off, not merely discouraged

No raw prompt, completion, retrieval corpus, model weight, clinical record, or financial record is requested or exported. An Evidence Record holds the finding. The raw-export flag is off by default and cannot be set from the browser.

Organisation isolation

Evidence, passports, visas, and decisions are isolated at the database and API layer. Nothing crosses an organisation boundary without an explicit, recorded act - a Wake, issued by a named person, to a named recipient.

Role-bound review

A reviewer sees only the decisions their role can defend. The DPO takes legal basis and special-category exposure; the CISO takes tools, credentials, egress, and logging. Every route enforces the check server-side - never in the client.

Evidence Records - the finding, not the data

A recorded result holds the finding - the check, the method and its version, the score - and never the data behind it. Signal Receipts carry an integrity hash computed by AffectLog when they are recorded.

The decision log is the record

Scan findings, passport issue and re-issue, visa grants, refusals, suspensions, and revocations are written to a per-organisation, append-only, hash-linked log with actor, role, timestamp, rationale, and resource. AI Act Art. 12 requires the events be recorded; this is where they are recorded.

Keys and secrets

Signing keys, API keys, and webhook secrets live in the environment, never in the database or version control.

Encryption in transit and at rest

Data is encrypted at rest by our database provider and in transit over TLS 1.2 or later. Payment webhook payloads are signature-verified before processing - and an entitlement activates only on a verified webhook event, never on a browser redirect.

No customer-hosted runner today

AffectLog does not yet offer a runner you deploy inside your own perimeter. Today the evidence you supply is recorded in AffectLog; raw records, corpora, prompts, and weights are not requested. If your context requires in-perimeter execution, tell us before you rely on AffectLog for it.

Evidence Records

The result is recorded. The raw input is never requested.

A recorded check produces one Evidence Record: the check, the method and its version, the parameters, the score, and the result. No input row, prompt, or document is included.

1You supply the evidence - a document, a summary, or a result
2The result is recorded - check name, parameters, and score only
3The record is dated and attributed to the person who recorded it
4It attaches to the passport section it supports
5A reviewer can view its recorded status at a public link

Evidence Record - anatomy

record_id:ER-2026-FAIR-082
check:group_disparity (AI Act Art. 10)
score:0.94
result:PASS
raw_data_included:false
timestamp:2026-05-06T09:14:22Z
integrity:hash recorded by AffectLog

Security HTTP headers

X-Frame-Options:DENY
X-Content-Type-Options:nosniff
Referrer-Policy:strict-origin-when-cross-origin
Permissions-Policy:camera=(), microphone=(), geolocation=()

Software Bill of Materials

A machine-readable SBOM in CycloneDX or SPDX format is available to enterprise customers on request. Third-party package notices are maintained in THIRD_PARTY_NOTICES.md.

Security disclosures

Coordinated disclosure. We respond within 48 hours.

Next

Bring the architecture to your review board.

We will walk your CISO and DPO through what AffectLog stores, the decision log, organisation isolation, and expiry - line by line, against your own deployment constraints.