Tamper-evident history
Every change is recorded and hash-chained, so alteration is detectable.
1D2A keeps decisions of record, so the questions people ask before adopting it are about evidence, durability and disclosure rather than features. This page answers them — including the ones where the answer is “not yet”.
Every change is recorded and hash-chained, so alteration is detectable.
Verified against the provider, kept 30 days, isolated from the application.
Tested automatically on every release. A regression blocks the deploy.
What we do not have is listed below, not left to be discovered.
A decision log is only worth keeping if you can prove what it said and when. Everything below exists today and is checked automatically.
A tamper-evident history. Every action that changes data writes an audit record — and no operation that changes data is without one, which an automated check enforces on every release. Records are hash-chained and sealed nightly, so alteration is detectable by anyone holding an earlier seal.
You can read your own trail. Organisation activity, a log’s history, a single decision’s history — and you can export an evidence bundle with a manifest and integrity hash.
Time-boxed auditor access. Grant read access to evidence within a scope you choose. It expires on a date you set and is revoked automatically.
Backups every night, kept 30 days, written to storage the application itself cannot reach. Each night’s run verifies that the previous night’s backup actually completed, so a silent failure surfaces within a day.
Uploads are scanned for malware before they can be downloaded, and fail closed: a file whose scan result cannot be read is not served.
OWASP ASVS 5.0 Level 2. All 253 Level 1 and Level 2 requirements assessed: 115 met, 31 provided by our cloud platform, 28 partial, 12 gaps. The gap list is available on request.
CIS Google Cloud Foundation Benchmark, all 84 controls assessed and dispositioned.
A bill of materials for every release. The application ships two runtime dependencies in the browser and three in the backend, audited on every change and weekly.
Accessibility to WCAG 2.2 AA, tested automatically against two tiers of the product on every deploy.
These are self-assessments, not third-party audits. We say so rather than implying otherwise, and the assessments are available if you want to check our working.
We name every third party that touches customer data, and give 30 days’ notice before adding one.
Data location. Everything is hosted in the United States. We do not currently offer EU or UK data residency. If that is a requirement for you, talk to us before subscribing rather than after.
Some features use OpenAI to draft or suggest content. This happens only when you actively use one — never in the background.
Your content is not used to train models. We use OpenAI’s API under its standard commercial terms, which exclude API data from training.
OpenAI retains it for up to 30 days for abuse monitoring, then deletes it. Deleting content from 1D2A does not shorten that window, and we say so rather than implying we can.
We do not store the text of AI requests in our audit records. We record that a request happened, from which feature, which model, and whether it succeeded — not what it said.
Several AI features work only if your organisation connects its own OpenAI account. Until it does, those features do not function and the content in your decision logs is not sent anywhere. Whether they are connected is visible in your organisation’s settings.
We would rather you learn this here than three weeks into an evaluation.
A page that lists only strengths tells you nothing, because every vendor has one. This list is what makes the rest of the page worth reading.
Data Processing Agreement, with standard contractual clauses and a transfer impact assessment.
Subprocessor register, the versioned source for the table above.
OWASP ASVS 5.0 Level 2 assessment, including the full gap list.
Accessibility Conformance Report covering WCAG 2.2, Section 508 and EN 301 549.
Software bill of materials for the current release.
The detailed security assessment maps closely onto where a system is weakest. Publishing our posture is useful; publishing a map is not. Ask and you will get it — there is no approval process and no NDA gate.
If you believe you have found a security issue, please report it by email. Include enough detail to reproduce it. We will acknowledge receipt and keep you informed.
Please do not test against other people’s data, and please give us a reasonable chance to fix an issue before disclosing it publicly.
1D2A is a personal project, not affiliated with any organization. Security reports and diligence questions reach the same person who writes the code.