CERTIMAND / Trust & security
Trust & security
Trust starts with knowing what exists today. This page describes the public Certimand MVP, last updated 5 September 2026.
What you can use today
The public demonstration runs deterministic checks over a fictional 150-person organisation. Its generative AI investigates selected synthetic findings, using source facts supplied by the server. You can download and independently replay a synthetic evidence package.
AI and human authority
AI explanations are proposals, not control decisions or legal advice. The interface displays the rule outcome separately. Source-reference validation checks that cited records exist; it cannot guarantee that every generated sentence is correct. Review the underlying facts before relying on an explanation.
The demo sends only server-owned synthetic records and a selected investigation intent to Google Vertex AI. It has no free-text AI prompt, customer upload or account-change capability. Contact-form content is not sent to the AI.
Hosting and data
The service is deployed on Google Cloud Run in Belgium (europe-west1). AI requests use the Google Vertex AI EU multi-region endpoint with Gemini 3.1 Flash-Lite. Website enquiries are backed up privately in a separate Google Cloud Storage bucket in the same region and forwarded through a contact service to a private Trello board for follow-up. Trello is an Atlassian service; we do not claim that Trello data is restricted to Belgium or the EU. Google is a US-headquartered provider; an EU region is not a claim of European sovereignty or the absence of international processing.
Cloudflare provides domain registration and DNS. With DNS-only records, it does not proxy application traffic. Google provides HTTPS, runtime and infrastructure logging. No advertising analytics, session replay or marketing trackers are included by the application.
Implemented boundaries
- Synthetic-only demo with no customer source credentials or identity uploads.
- Server-side validation, bounded request sizes and AI request limits.
- AI text rendered as text rather than executable HTML.
- Content Security Policy, frame restrictions and HTTPS.
- Private enquiry storage; the runtime can create records but has no public enquiry reading or listing route.
- Reproducible SHA-256 evidence manifests. These detect alteration relative to a manifest; they do not prove issuer authenticity.
Before a real customer connection
Customer use requires an agreed scope, contractual and data-processing terms, reviewed read-only permissions, tenant isolation, authenticated access, customer retention and deletion controls, backup restoration tests and incident ownership. Live Entra/GitHub connectors, customer account management and recurring collections are outside this public MVP.
Certimand does not currently claim ISO certification, independent penetration-test completion, qualified timestamps, 24/7 support, automated remediation or guaranteed audit acceptance.
Security contact
Use the Certimand contact form and start your message with “Security”. You can also contact the founder on LinkedIn. Do not send access tokens, passwords or raw customer identity files.
Read the website privacy notice · Inspect current control coverage