Your work is not training data
SuperEmber does not use private customer content to train public models.
You don’t have to trust us. Just know that the controls are operating, the evidence exists, and the only thing missing is the expensive independent audit and framed paper.
Things we can actually prove
Each promise maps to a named control below. The public summary stays readable while detailed evidence remains access-controlled.
SuperEmber does not use private customer content to train public models.
Eligible model requests are restricted to approved providers and ZDR endpoints.
Browser analytics stays off until consent and excludes prompts, messages, and names.
Workspace data and product operations are resolved inside explicit tenant boundaries.
Public control ledger
A customer-readable index of operating controls. No sensitive implementation details.
| ID | Area | Public control summary | Status |
|---|---|---|---|
| AI-01 | Model data handling | Private customer content is not used for SuperEmber model training. | Operating |
| AI-02 | Provider routing | Approved provider allowlist and ZDR endpoint restriction. | Operating |
| PR-01 | Browser analytics | Explicit consent; autocapture and session replay disabled. | Operating |
| AC-01 | Workspace access | Tenant-scoped authorization and pseudonymous analytics identity. | Operating |
| GV-01 | ISO 27001 control foundation | Operating ISMS controls and evidence for ISO/IEC 27001; independent certification not yet obtained. | Operating |
| GV-02 | Supplier assurance | DPA, region, transfer, deletion, and incident evidence register. | Operating |
| GV-03 | SOC 2 control foundation | Operating controls and evidence prepared for a SOC 2 Type I examination; no independent SOC 2 report yet. | Operating |
Compliance profile
The foundation is built and operating. What is missing is independent confirmation: the accredited audit, CPA report, and framed paper.
Privacy is not an optional add-on
SuperEmber is based in the EU. GDPR is a legal obligation, not an aspiration or a paid badge. Our DPA, privacy operations, retention, supplier, transfer, and rights processes form part of the operating foundation.
Controls before certificate
The ISMS foundation, including scope, owners, risk method, policies, evidence, reviews, and corrective actions, is operating. SuperEmber is not currently ISO 27001 certified; the accredited certification audit is the missing step.
Controls before CPA report
The same control and evidence foundation supports SOC 2 Type I attestation. No SOC 2 report is currently available; independent examination by a licensed CPA firm is the remaining step.
How data moves
The detailed architecture remains private. This public path shows where responsibility changes.
Messages, files, and instructions you choose to share.
Tenant-scoped orchestration and policy enforcement.
ZDR-restricted processing through reviewed providers.
Results return to the channel or service you requested.
Material providers
Provider purpose and transfer information lives in the public register. Contractual evidence remains controlled.
Need additional assurance materials? Contact privacy@superember.ai.