Where uploads are provided for the Evidence Review tier, the following controls apply:
- Client and personal names are redacted and anonymised where practicable
- Original documents are deleted within 14 days of report delivery; only anonymised versions are retained for benchmarking
- Data residency is selectable: AU, US, or EU
- Restricted allowable document types may be enforced
- Dedicated tenancy is available for enterprise clients with enhanced control requirements

Where organisations prohibit document uploads entirely, an alternative is available: client staff perform artefact quality assessments using standardised checklists with signed attestations to the project sponsor.
Respondent confidentiality
The Assurance Report contains no verbatim quotes by default. Reports include role-level sentiment only — for example, whether perceptions of a dimension are positive, negative, or mixed, attributed to role rather than to named individual.
The Alignment Index records where stakeholder views diverge across dimensions. That divergence is documented as a governance signal attributed to role — never to a named person. The governance forum sees the disagreement; it does not say who said what.
The ordering executive controls output distribution. Delivery is eyes-only by default: the Sponsor, CIO, or commissioner receives the report first and decides what circulates, to whom, and in what form.

Technical controls
- Cloudflare WAF
- Encryption in Transit?
- Encryption at Rest?
- Source code quarantined?
- Access control/privilege?
- Password policy & MFA?
- Vulnerability management? What’s the codebase, etc?
- DLP?
- Backup?
- Logging/SIEM
- Document penetration testing after it’s done
- Separation of environments?
- How are changes managed?