Trust · Data Handling
The things that matter are on this page, not behind a form.
The scopes we request, how a receipt is built, and the data flow are here. What genuinely needs an NDA — the SOC 2 report, subprocessor detail — is one request away. Every claim is backed by an artifact: a document, a diagram, or a test you run yourself.
Verify it yourself
Run a revocation test yourself
Don't take “you can revoke it” on faith. We run a standing, scheduled revocation test with you: revoke the credential in your own identity provider, and watch access fail — including cached tokens and in-flight jobs — with the result logged. This is the artifact that turns a gatekeeper into a sponsor.
Runs on Claude, inside your own Anthropic account
Foundation runs on Claude in your Anthropic organization, on Anthropic's zero-data-retention tier — your prompts and the model's outputs are not retained. Your data resolves live from your systems for the life of a single request and is not stored by Foundation. Trucast's control plane sees the account of the work — who asked, what ran, which sources were touched — never the contents.
Nothing is written to Foundation storage along that path. The audit trail records only the account of the work.
Receipts, not records
Foundation keeps the receipts, not the records. It does not store your source content, prompts, model outputs, or quoted snippets. A receipt records:
- Who — the actor — a named seat on your roster
- What ran — the tool or computed method, and its version
- On what — a pointer to the source record touched (e.g. a Salesforce record ID) — a reference, not the field values
- Reproducibility — an inputs hash, so a computed number can be reproduced bit-for-bit from the log
- When & which run — a timestamp and correlation id
- Outcome — success or the kind of error, and any change that was approved
A commitment extracted from a call is surfaced to you and, once you approve it, written to your system of record. Foundation does not keep a copy. The audit trail is deliberate retention of provenance, not of your data — that distinction is the whole design.
Scoped access you create and revoke
Foundation connects to each source through a scoped credential you create in your own identity provider. Scopes aren't secrets:
- Salesforce — read-only on the objects in scope (Opportunity/Deal, Account, Engagement). No write, no delete.
- Zoom / Teams — read-only on meeting transcripts.
The exact OAuth scope strings for each connector are available on request.
Operator controls, and our own access
The approver is never the proposer. A valid login without a seat on the named roster is refused. Every operator and every action is attributed.
Trucast's own access to your environment is a named, scoped, audited seat on your roster — a partner role, not hidden admin access. Elevated read, governed write, every action attributed. You can see it, and revoke it, exactly like any other operator.
Staged rollout, reversible by design
A replica first (representative data, not your records), then read-only on live data, then governed writes — each one a proposal a named person approves, with written exit criteria at every step.
Revoke the credential and access ends immediately, including cached tokens. Because Foundation stores none of your content, there is nothing to purge but the credential itself; the audit trail (provenance, not content) is retained per your policy. Turn Foundation off, and your systems are exactly as they were.
Certifications, residency & subprocessors
- SOC 2 Type I complete today. Type II observation is underway, with the report expected in 2027. Type I is a design snapshot — we say so plainly. Report available under NDA.
- Hosting is US-based (Anthropic, Vercel, Supabase, Modal, WorkOS).
- Incident & breach notification: we notify affected clients of a confirmed security incident without undue delay, and no later than 72 hours after confirmation.
- Subprocessors: Anthropic (model), Vercel, Supabase, Modal, WorkOS. Perplexity is used for public research only, never your records. Full list under NDA.
Regulatory alignment
Mapped to DORA, PRA SS2/21, and OCC 2023-17: exit-planning, concentration and fourth-party risk (including the model provider as a critical ICT dependency), auditability, and human oversight. The mapping document is ready to forward to your risk committee.
What you can verify yourself
- Run the revocation test (standing, logged).
- Read the audit trail.
- Reproduce any number from its receipt.
- Inspect the replica before a single production record is touched.
If our data flow can't survive public daylight, it can't survive your architecture review.