Trust & security
Trust begins with explicit boundaries.
Security scope, data handling, authority boundaries, execution containment, verification, and evidence — stated honestly from current infrastructure and code.
01
Current security scope
Noetfield builds governed agent infrastructure: authenticated sessions, policy-gated execution APIs, durable runtime state, and exportable evidence bundles. Public surfaces run on Cloudflare Pages and Railway with environment-scoped secrets.
We do not claim SOC 2 Type II, ISO 27001 certification, regulatory approval, perfect security, or immutability unless explicitly evidenced on this page.
02
Data handling
Contact and intake forms collect work email, organization name, topic, and message text you submit. Request IDs (RID) thread async intake on the corporate site.
Product runtimes store session, project, and execution metadata required to operate governed workflows. See Privacy for collection and retention detail.
03
Identity and authority
Authenticated users bind to organization-scoped sessions. The control plane resolves whether a proposed Action Contract may execute — models and harnesses propose; they do not self-authorize.
04
Execution containment
Motors execute only authorized contracts inside bounded runtimes: idempotency keys, execution limits, recovery caps, and stop conditions. Tool access is policy-gated per capability registry.
05
Verification and change control
Independent verifiers judge evidence against stated acceptance criteria. Promotion of workflow, policy, or runtime changes requires explicit human authority — no silent self-modification in production.
06
Evidence and provenance
Execution produces traces, receipts, and replayable artifacts scoped to a stated boundary. Public proof items live on Proof with explicit status and scope labels.
07
Certifications and non-certifications
| Item | Status | Evidence |
|---|---|---|
| Export / evidence integrity checks (product) | DEMONSTRATED | Public proof index · first-party scope |
| SOC 2 Type II (Noetfield as company) | NOT CERTIFIED | No audit report published |
| ISO 27001 (Noetfield as company) | NOT CERTIFIED | No certificate published |
| ISO 42001 (Noetfield as company) | NOT CERTIFIED | No certificate published |
| Noetfield as customer certifier | NOT A CERTIFICATION BODY | Corporate boundary — About |
| Regulatory approval or universal correctness | NOT CLAIMED | Evidence scoped per Proof item |
08
Security contact
Security or privacy questions: Contact operations · operations@noetfield.com · include your Request ID when available.