SScleriteBusiness Advisory Return to workspace

Security & trust center

Your business material should be treated like business material.

Clear boundaries, private storage, and traceable records are built into every engagement. Below is what the current beta does—and what it does not claim to do.

Current safeguards documentedLimitations are stated without implying independent certification

Authenticated access

The workspace requires authenticated access. Mission queries verify the signed-in owner before returning records.

Private evidence storage

Uploaded files are stored in a private object bucket under owner- and mission-scoped keys. The application does not generate public file links.

Separated metadata

Mission records, file metadata, access identity, and integrity fingerprints are maintained separately from the original evidence objects.

Bounded authority

A submission authorizes analysis for that engagement only. It does not authorize publishing, purchases, external messages, or account changes.

What happens after submission

  1. 1
    Identity is checked

    The mission is tied to the authenticated account submitting it.

  2. 2
    Scope is recorded

    The business question, report preference, delivery request, and analysis-only permission are written to the engagement record.

  3. 3
    Evidence is isolated

    Accepted files enter private mission storage and receive a SHA-256 integrity fingerprint.

  4. 4
    Work remains traceable

    Intake, routing, retention, and processing events are added to the engagement history.

What Sclerite will not imply

  • No claim that a human professional reviewed an engagement unless that review actually occurred.
  • No claim of a completed malware scan until an active scanning service has certified the file.
  • No public evidence links or open customer document directory.
  • No use of a submission as permission to act outside the workspace.

Technology disclosure
Sclerite Review Desk is a software-based analysis service that may use artificial intelligence. It does not claim human professional review unless that review occurred. Outputs should be reviewed before consequential business action.

Improvements in progress

These items strengthen the current service. They are not presented as completed certifications, and no certification is implied.

Key and access-control review Continued deletion and retention verification Upload scanning and file-processing isolation Privacy terms, incident process, and security testing