Current operating boundary · 3 September 2026

Security is a written stop gate, not a marketing claim.

The paid parallel run is designed to minimise data movement and operational dependency. It does not bypass the customer's security, legal, procurement or DPO process.

Public intake

The website form collects event and contact metadata only. It must not be used to send evidence files, credentials, personal data, model weights or confidential customer material.

Project route

The default test uses a customer-controlled secure workspace. Audital does not require a production connection or an Audital-hosted evidence repository.

Access model

Access must be named, least-privilege, time-limited and protected by MFA. Browser-only and read-only access is preferred. If this cannot be agreed, work does not start.

Evidence scope

Customer-approved, point-in-time exports only. Raw transaction data, patient records, special-category data, source credentials and model weights are excluded by default.

AI processing

Customer project material is not submitted to a generative AI service unless the customer expressly approves that route in writing.

Decision authority

Audital organises the supplied record. The customer reviewer retains every governance, risk, audit and approval decision.

Default data route

Customer-controlled from selection to closeout.

  1. 01SelectCustomer lists approved exports and excludes unnecessary sensitive data.
  2. 02GrantCustomer grants named, time-limited access to its chosen secure workspace.
  3. 03OrganiseAudital maps the supplied record to the frozen reviewer questions inside the agreed boundary.
  4. 04ReturnPortable outputs are delivered to the customer-controlled workspace.
  5. 05CloseCustomer revokes access. Any permitted working copy is deleted on the agreed date and recorded.

Signature blockers

Every material item must be a verified fact, signed term or accepted exception.

  • The named workspace, data location and exact export list are approved by the customer.
  • Controller and processor roles, confidentiality and any required DPA terms are signed.
  • Named access, MFA, read-only settings where available and revocation ownership are recorded.
  • The retention date, deletion method and closeout evidence are written into the engagement schedule.
  • Incident contacts and the notification procedure are agreed.
  • Liability terms and any customer insurance requirement are resolved.

Claims Audital does not make

No certification or insurance status is implied.

Audital does not currently publish evidence of ISO 27001 certification, SOC 2 Type II certification, professional indemnity cover or cyber-insurance cover. It does not claim automatic procurement approval, regulator approval or zero risk. If a buyer requires any of these, that requirement must be resolved before signature.

For an engagement-specific security schedule, email contact@audital.ai. Do not attach customer evidence to the first message.