Evidence should reveal what is necessary not everything you know.
Evidence is processed in AffectLog's hosted service, in your organisation's isolated workspace. There is no customer-hosted runner today. AffectLog records documents, summaries and results about the system - not the raw records it processes - and every decision taken on them.
Evidence, not data
Documents, summaries, and results - never the raw records.
Hash-linked decisions
Every clearance decision is written to an append-only, hash-linked log
Role-bound review
Server-side checks; no one reviews what they cannot defend
Everything expires
Passports and visas expire by default - renewal is a new decision
Security principles
Eight controls. On by default. Not configurable off.
Raw export is off, not merely discouraged
No raw prompt, completion, retrieval corpus, model weight, clinical record, or financial record is requested or exported. An Evidence Record holds the finding. The raw-export flag is off by default and cannot be set from the browser.
Organisation isolation
Evidence, passports, visas, and decisions are isolated at the database and API layer. Nothing crosses an organisation boundary without an explicit, recorded act - a Wake, issued by a named person, to a named recipient.
Role-bound review
A reviewer sees only the decisions their role can defend. The DPO takes legal basis and special-category exposure; the CISO takes tools, credentials, egress, and logging. Every route enforces the check server-side - never in the client.
Evidence Records - the finding, not the data
A recorded result holds the finding - the check, the method and its version, the score - and never the data behind it. Signal Receipts carry an integrity hash computed by AffectLog when they are recorded.
The decision log is the record
Scan findings, passport issue and re-issue, visa grants, refusals, suspensions, and revocations are written to a per-organisation, append-only, hash-linked log with actor, role, timestamp, rationale, and resource. AI Act Art. 12 requires the events be recorded; this is where they are recorded.
Keys and secrets
Signing keys, API keys, and webhook secrets live in the environment, never in the database or version control.
Encryption in transit and at rest
Data is encrypted at rest by our database provider and in transit over TLS 1.2 or later. Payment webhook payloads are signature-verified before processing - and an entitlement activates only on a verified webhook event, never on a browser redirect.
No customer-hosted runner today
AffectLog does not yet offer a runner you deploy inside your own perimeter. Today the evidence you supply is recorded in AffectLog; raw records, corpora, prompts, and weights are not requested. If your context requires in-perimeter execution, tell us before you rely on AffectLog for it.
Evidence Records
The result is recorded. The raw input is never requested.
A recorded check produces one Evidence Record: the check, the method and its version, the parameters, the score, and the result. No input row, prompt, or document is included.
Evidence Record - anatomy
Security HTTP headers