Trust Foundation
Trust, in five places.
Buyers and security teams ask the same questions in the same order. We've put the answers in five dedicated pages, each one as honest as we can make it. Where we're not all the way there yet, we say so.
Trust Foundation pages
Security
LiveHow we protect your data - six promises, twenty answers, and a deep architecture page for security teams.
Read moreCompliance
LiveWhere we stand on SOC 2, GDPR, HIPAA, ISO 27001, and the Data Processing Agreement. Honest, dated, no spin.
Read moreGovernance
LiveAdmin controls, audit log, retention, role-based access, and the bring-your-own-key roadmap.
Read moreResponsible AI
LiveOur no-train commitments, model selection rationale, hallucination guardrails, and prompt-injection defenses.
Read moreSub-processors
LiveThe companies that help us run Pocodot - what they do, what they see, and our 30-day notice promise.
Read more
Also useful
- Security architecture
The long technical version, written for security teams running a vendor review.
- Deletion-certificate signing key
Verify our workspace-deletion certificates yourself, on any platform, in 30 seconds.
- security.txt
Researcher disclosure path, PGP key, and scope (RFC 9116).
- Live status
Real-time platform status and incident history.
Have a vendor review to run?
We turn around most security questionnaires in one business day. Bring your CAIQ, SIG-Lite, or your own.