Permission is a filter on the query.

Security

A contract states what may be done with data. TRIVDA decides it, on every request, before anything is scored or returned. What follows is how that is built, what is written down, and what we have not built yet.

Enforced at
the index boundary
Recorded in
a hash-chained ledger
Read and indexed on
machines we run
A canal lock seen from its lower gate: the water held back in the chamber, a thin fall let through beneath the beam.
Canal lock, Grand Union Canal, Berkhamsted. Photograph Gabriel McCallin

What a request passes through.

  1. 01

    Authentication

    Every call carries a key or a token tied to one organisation. Keys are stored as Argon2 hashes, are shown once, and stop working the moment they are revoked: revocation is re-checked on every request rather than cached. An access token issued before a client was revoked lives out its hour.

  2. 02

    The index filter

    Before anything is scored, the query is narrowed to what this organisation may see: its own data, plus datasets whose owners have offered them, and only those that cleared the rights gate and meet the readiness floor. A passage you may not retrieve is never ranked, and the reranker never sees it.

  3. 03

    The owner’s terms, per passage

    Each surviving passage is then checked against the use you asked for, its sensitivity tier and its jurisdiction. A passage licensed for search does not answer a training request. A request can raise the readiness floor it will accept; it can never lower it.

Letters filed upright in numbered wooden slots, each one in its own compartment.
Photograph Carol Jeng

Nothing is indexed on trust.

Data earns its way into the index. These are not scores to be weighed against each other: failing one is disqualifying, and the material is quarantined instead.

A declared licence
An identifier from a known list. Missing or unrecognised means quarantined, not indexed.
A warranty on file
The owner’s statement that they are entitled to license it. Without one, every use is denied, including uses they granted.
A lineage record
Where the material came from, what read it, and when. Without it the passage cannot be published.
Personal data, banded and screened
Every passage is given a sensitivity band on the way in. Direct identifiers are masked in place and the band is then blocked from retrieval rather than trusted to the masker. Special-category data is quarantined rather than masked, so it is never indexed at all.

Every decision is written down.

Ledger entry access
Event
access
Decision
permitted
Use case
rag
Dataset
acme-maintenance
Organisation
org_4c19Who asked. Not who at that organisation.
Returned
3 passagesHow many. Never what they said.
Prev
sha256:77ae…The hash of the entry before this one.
  • Hash-chained, so an edit shows

    Each entry hashes the one before it. Changing an old entry breaks every entry after it, and verification walks the chain from the first one to prove it has not happened.

  • Ids and hashes only

    The ledger records that a passage was returned, not what it said. Content appears as a hash and people as keyed pseudonyms, so the log itself never becomes the leak.

  • Refusals are recorded too

    A blocked request, a denied training attempt and a refused export are recorded as carefully as a permitted read. A log of only the permitted ones proves nothing.

  • Erasure leaves a record

    When an owner invokes erasure, the passages leave the index, the identifier is suppressed against re-ingestion, and the act itself is written to the chain.

What we do not do with a partner’s data.

Four things that cannot happen, whoever asks for them.

We do not send it out to be read

Parsing, optical character recognition and transcription all run on our own machines. Hosted document and speech services are excluded for partner material, and cloud processing is off unless an organisation turns it on.

We do not train on it

TRIVDA does not train models on partner data. Training is a licence a partner grants to a named buyer, not something the platform helps itself to.

We do not widen access by default

A dataset’s contents stay inside the organisation that uploaded it until its owner offers it. Nothing shares it automatically. Its catalogue record, not its contents, is visible to other organisations unless the dataset is marked internal.

We do not let one customer see another’s questions

Your query text is kept in your own activity log, where your team can read it back. It is not written to the audit chain, and no other organisation can reach it.

Anything this page does not answer.

The trust centre has the documents, the subprocessors, what is stored and for how long, the status of every framework we are asked about, and how to reach us about a vulnerability.