Who owns the data
- The organization owns its intelligence record and every document behind it. Attesta is never the owner or controller of that data; where a pilot involves organizational data, the intended arrangement is that Attesta handles it only on the organization's written instructions. The exact legal characterisation is settled in the data processing agreement, not asserted here.
- An institution's assessments, notes, and lens configuration belong to that institution.
- Attesta does not sell, license, syndicate, or resell organizational data to any third party. There is no public directory and no marketplace.
- At the end of a pilot, both sides receive an export of everything created during it.
What this prototype does and does not do today
- The product workspace you can explore is a prototype running on illustrative data in your browser. Nothing you type into it is transmitted or stored on a server.
- The only data Attesta stores today is anonymous product-research telemetry, optional feedback, and pilot commitment details you deliberately submit.
- There are no automated data integrations yet. Pilot records are built manually from documents you provide.
- No SOC 2, ISO 27001, HIPAA, or PCI compliance is claimed or in progress. Do not enter regulated or confidential data into the prototype.
Security posture during a pilot
- Data is stored on managed cloud infrastructure operated by Supabase on Amazon Web Services. Encryption in transit (TLS) and at rest is provided by those platforms; Attesta has not built or independently audited any additional security controls.
- Attesta is a single-founder company. In the current research and pilot environment, the founder's account is the only one with administrative access, and there is no support team with standing access. There is no formal access-review process yet.
- This prototype is not ready for sensitive, confidential, or regulated institutional data. Pilots should use synthetic, public, redacted, or otherwise non-sensitive data.
- Real organizational data is only accepted after a signed data processing agreement and a named scope.
Retention and deletion
- Current operating practice, carried out manually by the founder: pilot data is deleted within 30 days of pilot close unless you ask in writing for it to be retained. There is no automated retention job yet.
- Research telemetry is anonymous and contains no contact details unless you explicitly consented to follow-up.
- If you did not consent to follow-up, contact fields are discarded before storage and blocked at the database level.
- You can request deletion of anything you submitted at any time. Current practice is to action it within five business days; this is a manual commitment, not an automated guarantee.
How we research institutions before contacting you
- If we approached you, we identified your institution from public information only: government award and opportunity records, IRS Form 990 filings published by ProPublica, the CDFI Fund's published certification list, and your own newsroom or careers pages.
- We do not purchase contact lists, scrape gated or login-protected sites, or use personal-data enrichment services.
- We record a short internal note about why the timing looked relevant — for example a published funding round or an open opportunity — together with a link to the public source. Nothing else about you is stored.
- Prospect notes are readable only by the founder account and are never shown inside the product, shared with other institutions, or used to rank or list organizations anywhere.
- You can ask us what we hold about your institution, or ask us to delete it, and we will action it within five business days.
Who to contact
- General questions about Attesta: hello@attesta.work
- Pilots, partnerships, agreements, invoices, and payments: partnerships@attesta.work
- Data requests, deletion requests, account help, and technical issues: support@attesta.work
- Email is monitored by the founder directly. There is no support queue, no ticketing system, and no third-party helpdesk holding your correspondence.
Documents available on request
- Mutual non-disclosure agreement
- Data processing agreement, including subprocessor list
- Written pilot scope with success criteria and dates
- Security questionnaire responses, answered honestly for an early-stage company
Draft policy documents
Published early so your legal and risk teams can read them before anything real is exchanged. All are founder-authored drafts, not reviewed by counsel, and not legal advice.
Privacy NoticeWhat Attesta collects on the demonstration site and in pilot workspaces, why, and how to have it deleted.Terms of UseThe conditions under which the demonstration site and pilot workspaces may be used.Security PracticesThe controls that exist today, stated plainly, along with the ones that do not.Data HandlingWhere data lives, who can reach it, and what happens to it during a pilot.Retention, Export, and DeletionHow long data is kept, how to get it out, and how to have it removed.Incident ResponseWhat Attesta does if something goes wrong, and what to expect as a participant.Pilot Data ScopeExactly what data a pilot needs, what it will not accept, and who touches it.