Trust, plainly stated.
The controls that exist today, the standards we align to, and the ones we are still preparing for. No certification claim we do not hold.
HOW YOUR DATA IS PROTECTED
Row-level security on every table. Cross-tenant reads go through security-definer functions, never loosened policies.
AI provider keys live in a sealed table with no client policies. The client sees a label and last four characters, nothing else.
TLS for every request. Data at rest is encrypted by the managed backend.
Patterns detected inside your account never leave it. What can travel to the shared library is a de-identified abstraction: a role family, a task family and counts, released only when at least three people across at least three companies show the same shape, and only after a human review. No text, no names, no company, no numbers you did not log.
Every AI call is server-side and logged. Organizations can plug their own providers, including on-prem or local endpoints.
STANDARDS · CONTROL AND INDEPENDENT VERIFICATION
Two statuses on every row, never one.
Two separate things sit on every row. CONTROL is what ARK built and runs today. INDEPENDENT VERIFICATION is whether anyone outside ARK has checked it, and it reads PENDING until an outside party grants it in writing.
The percentage on a standard counts controls ARK built. It says nothing about certification, and it never will. Today no outside party has certified or reviewed any row on this page, so every verification chip reads PENDING with the party it needs named beside it.
- IMPLEMENTEDPENDINGPrivacy notice and lawful basisPrivacy policy published at /legal/privacy.NEEDS · Privacy counsel redlines.
- IMPLEMENTEDPENDINGData Processing AgreementDPA available at /legal/dpa.NEEDS · Privacy counsel redlines.
- IMPLEMENTEDPENDINGSubprocessors disclosedSubprocessors list at /legal/subprocessors, with purpose and region.NEEDS · Privacy counsel completeness check.
- IMPLEMENTEDPENDINGData subject exportOne-tap GDPR data export in the app, as JSON.NEEDS · Privacy counsel to confirm the export reaches every table.
- IMPLEMENTEDPENDINGRight to erasureAccount and data deletion supported, honoured within 30 days.NEEDS · Privacy counsel to confirm deletion reaches every table.
- IMPLEMENTEDPENDINGTenant isolation and data minimizationRow-level security on every table, owner or team-member scope only. No special-category data is collected or inferred.NEEDS · An application-security tester to attempt cross-tenant reads. Brief written and ready to send.
- IMPLEMENTEDPENDINGDocumented breach responseWritten runbook with the 72-hour clock, severity path, the Latvian lead authority named, and notification templates.NEEDS · Privacy counsel to review the notification path.DOC · docs/trust/breach-response-runbook.md
- IMPLEMENTEDPENDINGRisk classificationLimited-risk system, argued line by line against Article 5 and Annex III in the technical file.NEEDS · Counsel to confirm the classification argument.DOC · docs/trust/ai-act-technical-file.md
- IMPLEMENTEDPENDINGArticle 4 AI literacyLiteracy is the product. Measures for learners, for organisational deployers and for the operator are documented with where each one's evidence sits.NEEDS · No outside party has checked this. ARK's own testing only.DOC · docs/trust/ai-act-article-4-evidence.md
- IMPLEMENTEDPENDINGTransparency, Articles 13 and 50ARK System Generated content is labeled, projected figures read MODELLED NOT MEASURED, and every model call is logged in the MODELS USED report.NEEDS · No outside party has checked this. ARK's own testing only.
- IMPLEMENTEDPENDINGHuman oversightGuest-first, a person keeps or discards every output, no autonomous action on user systems.NEEDS · No outside party has checked this. ARK's own testing only.
- IMPLEMENTEDPENDINGNo prohibited practicesNo manipulation, no scoring of persons, no biometric use. Per-person use of a modelled read is a contract breach.NEEDS · Counsel to confirm.DOC · docs/trust/ai-act-technical-file.md
- IMPLEMENTEDPENDINGTechnical documentationTechnical file covering purpose, classification, transparency, data governance, accuracy, logging and post-market monitoring.NEEDS · Counsel to review the file.DOC · docs/trust/ai-act-technical-file.md
- IMPLEMENTEDPENDINGAccess control and least privilege · CC6Row-level security plus managed auth. Cross-tenant reads go through security-definer functions. Provider keys sealed server-side with no client policy.NEEDS · CPA firm testing.DOC · docs/trust/soc2-information-security-policy.md
- IMPLEMENTEDPENDINGEncryption in transit and at restTLS in transit, encrypted at rest via the managed backend.NEEDS · CPA firm testing.
- IMPLEMENTEDPENDINGAudit logging · CC7.1ai_call_log holds every model call, alert_events holds every alert firing, interaction_events holds product interactions as ids and enums.NEEDS · CPA firm sampling over an observation window.DOC · docs/trust/evidence-index.md
- IMPLEMENTEDPENDINGChange management · CC8.1Every schema change is an ordered migration, tested against a clean environment. The deterministic eval suite gates every change. Full commit history retained.NEEDS · CPA firm to sample changes.DOC · docs/trust/soc2-information-security-policy.md
- IMPLEMENTEDPENDINGVendor management · CC9.2One provider registry for every AI vendor, bring-your-own keys including local endpoints, and a public subprocessor list kept current.NEEDS · CPA firm review.
- IMPLEMENTEDPENDINGMonitoring and incident response · CC7.2 to CC7.4Alerting layer with six watches, dedupe and cooldown, mail at high severity. Nightly backups with a manifest and a tested restore. Written incident-response policy with a severity table.NEEDS · CPA firm to observe the response path over a window.DOC · docs/trust/soc2-incident-response-policy.md
- IMPLEMENTEDPENDINGSecurity policiesInformation-security policy and incident-response policy written, scoped and versioned, with a risk register and an exception rule.NEEDS · CPA firm review.DOC · docs/trust/soc2-information-security-policy.md
- PLANNEDPENDINGIndependent penetration testNot run. The scope brief is written, naming tenant isolation and key containment as the first two questions.NEEDS · An application-security firm with multi-tenant Postgres experience.DOC · docs/trust/reviews/security-review-brief.md
- IMPLEMENTEDPENDINGAI management system policyAIMS policy written against the clause structure: objectives with a measure each, the accountable person, operational controls and the improvement rule.NEEDS · Certification body, stage one.DOC · docs/trust/iso42001-aims-policy.md
- IMPLEMENTEDPENDINGAI system inventory and risk classificationFourteen systems listed by capability, each with its input, its output, its human oversight and its deterministic fallback.NEEDS · Certification body, stage two.DOC · docs/trust/iso42001-ai-system-inventory.md
- IMPLEMENTEDPENDINGData governance for AIA table of what reaches a model and what never does, the identity strip, the private-lane exclusion, retention, residency and the ingestion rule.NEEDS · Certification body, stage two.DOC · docs/trust/iso42001-data-governance.md
- IMPLEMENTEDPENDINGModel and provider governanceCapability-based gateway, per-org provider chains, one file allowed to name a model, daily caps, BYO keys including local endpoints, full call log.NEEDS · Certification body, stage two.
- IMPLEMENTEDPENDINGTransparency to usersARK System Generated content labeled, modelled figures marked, and this page splits what ARK built from what an outside party has checked.NEEDS · No outside party has checked this. ARK's own testing only.
- IMPLEMENTEDPENDINGHuman oversightA person keeps or discards every output, and that decision is the product's primary quality signal.NEEDS · No outside party has checked this. ARK's own testing only.
- IMPLEMENTEDPENDINGAI impact assessmentSeven assessed impacts across learners, teams, modelled occupations and named third parties, each with controls, residual risk and a verdict.NEEDS · Certification body to review the assessment.DOC · docs/trust/iso42001-ai-impact-assessment.md
- IMPLEMENTEDPENDINGContinuous evaluationThree legs, all deterministic: the eval suite on every change, the calibration ledger for projections that were later checked, and the fairness invariance checks.NEEDS · An algorithmic-fairness practice for the bias leg. Brief written and ready to send.DOC · docs/trust/iso42001-aims-policy.md
- IMPLEMENTEDPENDINGAggregate-only reads with a three-person floorDefiner reads return roles at levels. There is no per-person projection to retrieve.NEEDS · Security tester to attempt a walk-around of the floor.
- IMPLEMENTEDPENDINGProhibited use clause in client contractsVersioned clause, published at /trust/prohibition, forbidding use against a named person.NEEDS · Counsel to review enforceability.
- IMPLEMENTEDPENDINGFairness method notePublished on this page: the invariance check, its axes, its tolerances and its limits, with the internal-check label kept on it.NEEDS · An algorithmic-fairness practice. Brief written and ready to send.DOC · src/lib/fairness/method.ts
- PLANNEDPENDINGValidation note, back-test accuracyNot written. It arrives with the validation pack, once the closed back-test count the selling gate asks for is reached.NEEDS · A measurement scientist, after the back-tests close.
THE DOCUMENT SET
Every policy behind those rows, written down.
These are ARK's own documents, versioned in the repository beside the code they describe. Buyers, auditors and counsel can ask for any of them, and the auditor index says where each control's evidence sits.
What happens in the first 72 hours: who declares it, how it gets contained, how the risk is judged, who gets told and when. The Latvian lead authority is named and both notification letters are already written.
The provider's own technical documentation. What ARK is, why it lands as limited-risk against Article 5 and Annex III, how transparency and human oversight work, and how the system is watched after release.
AI literacy is the product, so the evidence is the product. Every measure is listed with the table or file it can be read from, for learners, for organisations deploying ARK, and for the operator.
Scope, roles, access control, change management, logging, backup, vendors and the risk register, written against the Trust Services Criteria and mapped to the controls that already run.
Three severities with acknowledge and contain times, the seven-step response, the post-incident rule that every failure has to produce a migration, an eval or an alert, and the yearly test.
The AI management system policy: objectives with a measure each, the accountable person, the operational rules that constrain every model call, and how performance gets read quarterly.
All fourteen AI systems ARK runs, described by the capability they ask for rather than a model name, each with its input, its output, who oversees it and its deterministic fallback.
A table of what reaches a model and what never does, the identity strip, the private lane, retention, where processing happens, and why ingested material is data and never instruction.
Seven ways this could hurt somebody, from a level read wrongly to an aggregate used against a named person, each with its controls, the risk that stays, and a verdict with conditions attached.
Where every SOC 2 and ISO 42001 control's evidence lives, criterion by criterion, so a CPA firm or a certification body can scope without a discovery call. It also lists plainly what is not there.
For a security questionnaire, write to hello@shift.studio and name the document.
INDEPENDENT REVIEWS · SCOPED, NOT YET COMMISSIONED
Four reviews ARK has written the brief for.
None of these has been commissioned, so none of them appears as a verification anywhere on this page. Each brief states the one question the reviewer answers, what ARK hands over, and which artifacts to open first. When a review lands, the reviewer's name, date and scope go up here, favourable or not.
The level engine and its thresholds, the evidence model, the fairness checks, the verified workflow proofs as an outside criterion, the calibration ledger, and de-identified level distributions with counts.
Full source and migration history, every policy and definer function with its grants, test accounts across two organisations plus a non-member, the public endpoint list, and a contact answering within a business day.
The schema with retention per table, the migration history, the published notice, DPA and subprocessor list, the telemetry rule, the private-lane exclusion, and a live walkthrough of an export and a deletion.
Every fairness check with its axes and tolerances, the rigged-subject tests that prove it catches injected bias, the identity strip, the run register, outcome distributions with a minimum cell size, and new evidence sets built to the reviewer's design.
FORESIGHT · THE METHOD AND ITS LIMITS
What a FORESIGHT scenario is, and what it may never be used for.
FORESIGHT is organizational planning analytics on modelled scenarios. It is never to be used for decisions about an individual employee or candidate, and no individual-level output exists.
A FORESIGHT run reads an occupation, a level band and a headcount. It never reads a person, a record, a capture or anything anybody wrote. The ability to look at one employee is absent from the path rather than switched off in a setting.
Any cell holding fewer than 3 people is withheld from every read, and the report prints how many cells were withheld. Small cells are dropped rather than blurred, because a blurred cell is still a cell about people.
Every figure is a projection over published occupational task data plus a headcount, moved by an epoch offset and by assumptions that are printed beside the number. Measured results live on the proof surfaces and carry the opposite label. The two never share a page.
A scenario is planning input. It supports a decision about a program, a sequence or a budget. It does not support a finding about a person, and it is not offered as one.
FORESIGHT is organizational planning analytics on modelled scenarios. It is never to be used for decisions about an individual employee or candidate, and no individual-level output exists.
FORESIGHT scenarios are shown as a labelled preview; sold results are gated on at least 5 closed calibration back-tests. Until that ledger fills, what you see is labelled as a preview wherever it appears.
FORESIGHT scenarios are shown as a labelled preview; sold results are gated on at least 5 closed calibration back-tests.
The back-test protocol, the closed calibration record, and the accuracy the ledger reports. Published alongside the 5 closed back-tests the selling gate asks for.
FAIRNESS METHOD NOTE
How we test FORESIGHT and the level engine for fairness.
INTERNAL CHECK · NOT AN INDEPENDENT AUDITWe hold capability constant, change only the surface of the writing, and check that the outcome stays put. This is a modelled internal test on invented evidence, not a certified audit of ARK.
We write evidence sets by hand, then render each one several ways: formal and casual phrasing, and the same content in English, Latvian and German. The level engine, the AI-exposure read and the voice gate run over every version. If a placement moves because somebody writes casually or writes in Latvian, that is a bug and the run fails on it. The tolerance is stated: a rung may not move at all, a share may wobble by one point.
Across the set we report outcomes by occupation group, level band and locale, and check that identical evidence lands on the identical rung whichever occupation group it sits in. AI-exposure shares do differ between occupations, because the published task data differs. That is data, not bias, so only the rung is held to equality.
ARK holds no data on race, gender, age, health or belief, and the fairness harness does not infer any of it. The groups it reports on are occupation group, level band and language. Nothing in the harness touches a member's rows: every piece of evidence in it is invented for the test.
One variant plants name-shaped tokens into the evidence on purpose, so the run can prove the identity strip removed them before any engine read the text. A single surviving token fails the run.
It is a synthetic internal check that we run and read ourselves. It is not a bias audit, it is not certified, and no outside party has signed it. The independent review stays owner-side and we will publish it here when it exists, with whoever ran it named. Until then, treat this note as our own testing, openly described.
THE TRUST PACK
HAND IT TO YOUR IT TEAM
ADOPT A POLICY FOR THE PILOT
YOUR DATA RIGHTS
One-tap export of every record tied to your account, as JSON, from the app settings panel.
Delete your account and its data at any time. Deletion is honoured within 30 days.
Report a vulnerability: security@shift.studio. Response within 48 hours.