Audit log integrity

Chain verified ✓

Every vote, problem submission, idea, login, and role change is written to a hash-chained, append-only log. This isn't a claim — the badge above is a live result of recomputing every hash right now, 223 entries deep.

ActionActorTargetHashWhen
login human #2 user #2 fb0f13d35c… 11:43:08
distribution_added demo_teammate #13 problem #36 f0c9c0cad9… 12:29:45
campaign_launched demo_teammate #11 problem #36 a96fb86e4f… 12:29:26
product_listed demo_teammate #12 problem #36 3492b15c63… 12:29:01
test_report demo_teammate #10 problem #36 b24eb6b5f0… 12:28:48
build_submitted demo_teammate #9 problem #36 91eab27883… 12:28:33
test_report demo_teammate #10 problem #36 ad96a47771… 12:28:03
build_submitted demo_teammate #9 problem #36 4f5c2e12ef… 12:27:15
funding_pledge demo_teammate #8 problem #36 4b2dea3d57… 12:26:45
idea_selected human #2 problem #36 d422ef92db… 12:26:21

SOC 2 — Trust Services Criteria (target, not yet audited)

This is an honest status: the architecture is built around all five AICPA criteria, but no third-party SOC 2 audit has happened yet — that's a milestone tied to the Investor/payments launch, not to this Phase 1 build.

Security

Session-based auth, hashed passwords, role-based access checks on every write route.

Availability

Not yet applicable at Phase 1 scale — no uptime SLA published yet.

Processing Integrity

Hash-chained audit log (live above), unique-constraint-enforced one-vote-per-user-per-target.

Confidentiality

Passwords hashed with Werkzeug/PBKDF2, never stored in plaintext.

Privacy

No third-party data sharing yet; a real Privacy Policy is still an outstanding legal task (see the Legal Scaffolding doc).

AI guardrails

No AI features are live in this Phase 1 build yet — the Concierge page is a preview only, not wired to a live model. When AI features do ship, they follow the guardrails designed in the platform strategy docs: advisory and cited, never autonomous with money.