SecurePM
Trust center

Evidence your security team can verify before purchase.

SecurePM is v0 and design-partner stage. We publish reproducible proofs — not customer logos — so reviewers can inspect boundaries, egress, and audit traceability themselves.

Review assets

Start here for procurement and security review.

Security FAQ

Twenty pre-answered questionnaire items: residency, subprocessors, training, auth, audit.

Read security FAQ →
Deployment checklist

Week-by-week rollout steps for Cloud, Data Center, and air-gapped paths.

Open checklist →
Live test drive

Turn a rough product note into a Jira-ready issue, then review project fields, sources, and the content boundary.

Run test drive →
Machine-verifiable proofs

Run these commands during review.

GET  https://api.securepm.dev/egress
curl -sS https://api.securepm.dev/egress | jq
# Expect: only your model endpoint — never securepm.dev

curl -sS https://api.securepm.dev/attestation | jq
# Signed Ed25519 statement of the egress allowlist

curl -sS https://securepm.dev/api/privacy | jq
# Content-free licensing boundary (control plane)

Pin the public key from /attestation and verify offline with the MIT @opensyber/spm-attest CLI shipped in this repo.

Traceability

What gets logged in your tenant.

RecordWhereFields
Draft audit rowCustomer D1actor, project, intent, model, citations, fields_set, warnings, compliance_action
Validator rejectionsSame audit rowwarnings_text with per-field reasons
Compliance blocks422 response + auditcompliance_action = block_draft | require_approval
License checkVendor control planekey, opaque instance id, content-free draft count only
Honest posture

What we do not claim yet.

No SOC 2 yet

v0 design-partner stage. Architecture is built for buyer-owned audit; formal certification is deferred.

No customer logos

Evidence is reproducible tests and live endpoints, not reference customers.

Rename pending

SecurePM is a working codename. Marketplace listing waits on validation GO.

Full packet

Need the complete security packet?

Architecture one-pager, CI gate suite, compliance pack mapping, and questionnaire answers for your review email.

Request packet