1D2Abetter decisions
Trust

Security and Trust

1D2A keeps decisions of record, so the questions people ask before adopting it are about evidence, durability and disclosure rather than features. This page answers them — including the ones where the answer is “not yet”.

Self-assessed Last updated 24 August 2026 4 min read
At a glance

Tamper-evident history

Every change is recorded and hash-chained, so alteration is detectable.

Nightly backups

Verified against the provider, kept 30 days, isolated from the application.

WCAG 2.2 AA

Tested automatically on every release. A regression blocks the deploy.

Published gaps

What we do not have is listed below, not left to be discovered.

01

What we can show you

Why this matters

A decision log is only worth keeping if you can prove what it said and when. Everything below exists today and is checked automatically.

Evidence

A tamper-evident history. Every action that changes data writes an audit record — and no operation that changes data is without one, which an automated check enforces on every release. Records are hash-chained and sealed nightly, so alteration is detectable by anyone holding an earlier seal.

You can read your own trail. Organisation activity, a log’s history, a single decision’s history — and you can export an evidence bundle with a manifest and integrity hash.

Time-boxed auditor access. Grant read access to evidence within a scope you choose. It expires on a date you set and is revoked automatically.

Durability

Backups every night, kept 30 days, written to storage the application itself cannot reach. Each night’s run verifies that the previous night’s backup actually completed, so a silent failure surfaces within a day.

Uploads are scanned for malware before they can be downloaded, and fail closed: a file whose scan result cannot be read is not served.

Assessed, and published

OWASP ASVS 5.0 Level 2. All 253 Level 1 and Level 2 requirements assessed: 115 met, 31 provided by our cloud platform, 28 partial, 12 gaps. The gap list is available on request.

CIS Google Cloud Foundation Benchmark, all 84 controls assessed and dispositioned.

A bill of materials for every release. The application ships two runtime dependencies in the browser and three in the backend, audited on every change and weekly.

Accessibility to WCAG 2.2 AA, tested automatically against two tiers of the product on every deploy.

In plain terms

These are self-assessments, not third-party audits. We say so rather than implying otherwise, and the assessments are available if you want to check our working.

02

Where your data goes

We name every third party that touches customer data, and give 30 days’ notice before adding one.

Google Cloud / Firebase
Hosting, database, authentication, file storage — United States
OpenAI
AI drafting features — United States
Twilio SendGrid
Invitation and notification email — United States
Plausible Analytics
Cookie-less usage analytics — European Union
Google reCAPTCHA
Abuse prevention — United States

Data location. Everything is hosted in the United States. We do not currently offer EU or UK data residency. If that is a requirement for you, talk to us before subscribing rather than after.

03

AI features

Some features use OpenAI to draft or suggest content. This happens only when you actively use one — never in the background.

Your content is not used to train models. We use OpenAI’s API under its standard commercial terms, which exclude API data from training.

OpenAI retains it for up to 30 days for abuse monitoring, then deletes it. Deleting content from 1D2A does not shorten that window, and we say so rather than implying we can.

We do not store the text of AI requests in our audit records. We record that a request happened, from which feature, which model, and whether it succeeded — not what it said.

Whether your log content reaches AI at all

Several AI features work only if your organisation connects its own OpenAI account. Until it does, those features do not function and the content in your decision logs is not sent anywhere. Whether they are connected is visible in your organisation’s settings.

04

What we do not have

We would rather you learn this here than three weeks into an evaluation.

SOC 2
No report, and none in progress. We will start when a customer needs one — expect 6–15 months from that point.
ISO 27001
No.
Penetration test
Not yet conducted. The scope is written and ready for a vendor.
Multi-factor authentication
Not available. This is our most significant security gap and we do not dress it up.
Single sign-on and SCIM
Not built. On the roadmap.
EU / UK data residency
Not offered.
Tested recovery time
Backups run and are verified, but a full restore drill has not yet been performed, so we publish no recovery-time figure.
24/7 alerting
Failures notify the service owner by email. There is no on-call rotation.
Why this list is here

A page that lists only strengths tells you nothing, because every vendor has one. This list is what makes the rest of the page worth reading.

05

Documents

On request

Data Processing Agreement, with standard contractual clauses and a transfer impact assessment.

Subprocessor register, the versioned source for the table above.

OWASP ASVS 5.0 Level 2 assessment, including the full gap list.

Accessibility Conformance Report covering WCAG 2.2, Section 508 and EN 301 549.

Software bill of materials for the current release.

Why some are on request

The detailed security assessment maps closely onto where a system is weakest. Publishing our posture is useful; publishing a map is not. Ask and you will get it — there is no approval process and no NDA gate.

06

Reporting a vulnerability

If you believe you have found a security issue, please report it by email. Include enough detail to reproduce it. We will acknowledge receipt and keep you informed.

Please do not test against other people’s data, and please give us a reasonable chance to fix an issue before disclosing it publicly.

Security questions or a vulnerability report

1D2A is a personal project, not affiliated with any organization. Security reports and diligence questions reach the same person who writes the code.

ivan@ivanjureta.com