Every table that holds a customer's rows carries a row-level security policy, and the application connects as a role that cannot bypass it. A query with no tenant context returns no rows, whatever the code above it asked for. The sections below run in the order a questionnaire usually asks.

What the database answers
app.subscriber_id setn rowsapp.subscriber_id missing0 rows

Same table, same query, same role. The policy matches nothing, and the application is told so.

  • 0

    rows returned to a query with no tenant context

  • 5

    checks between the public edge and a row

  • 7

    access classes, from Subscriber Admin to Recipient

  • 35

    permissions those classes are built from

  • 14

    days an invitation link stays valid

Five checks

Where a cross‑tenant read is stopped

In the order a request meets them. Each check is made on its own.

  1. Check 1

    The edge

    Traffic reaches the application through an outbound tunnel with an access policy in front of it. No application port on the host answers the internet, and the host keeps its own firewall behind the cloud one. The administrative surface is a separate deployment on its own hostname, behind its own access gate.

  2. Check 2

    Signing in

    A password and a one-time code, or Microsoft Entra ID where the deployment enables it. The tenant is fixed into the session at sign-in and never re-read mid-session, so changing a record cannot move a live session into another tenancy.

  3. Check 3

    Inside a request

    API routes resolve the tenant before they read anything. The backstop sits below them: a route that forgets to scope a query gets no rows back.

  4. Check 4

    The database

    Row-level security on every tenant table, with the tenant set per transaction. The application connects as a role that cannot bypass those policies.

  5. Check 5

    Downstream services

    Search and source-code analysis receive a tenant identifier they cannot widen, and the token that reaches them names the project as well as the tenant.

Inside a project

Projects / Arden Systems / Team
Illustrative
PersonSeat

Subscriber Admin

H. Brennan · Your firm

Edits Documents, Request list, Report, Insights, Analyst files, Team

Counted

Project Lead

J. Lindqvist · Your firm

Edits Documents, Request list, Report, Insights, Analyst files, Team

Counted

Team Member

P. Adeyemi · Your firm

Edits Documents, Request list, Report, Analyst files · Reads Insights

Counted

Contributor

M. Okafor · Arden Systems

Edits Documents, Request list · Reads Insights

Not counted

Reviewer

S. Marsh · Invited expert

Reads Documents, Request list, Report, Insights, Analyst files

Not counted

Viewer

R. Costa · Your firm

Reads Documents, Request list, Insights

Not counted

Recipient

A. Whitfield · Lender's adviser

Reads Report

Not counted

A seat is held by anyone who can author or approve a finding, create a project or administer the workspace. Contributors, reviewers and recipients never hold one, and an invitation holds a seat from the moment it is sent.

Who sees what, by class

The 7 classes in the ledger decide what each person in a project can open. Remove a member and their access ends at once; a finding they signed off stays attributed to them. There is no repository role. The source-code extract is produced by the target's engineers inside their own network and uploaded by your team, so the person who produces it needs no account here.

Contributor

The target's people. They upload documents and work the request list, hold no seat, and can read insights. The Report tab and the analyst files are closed to them, and they cannot edit a finding.

Team member and Reviewer

Team member is the working role: reads the evidence, drafts and edits the report, holds a seat. Reviewer is read-only across the project, holds no seat, and is also the standing an outside reader has when a review round asks them to mark up an issued release.

Recipient

Reaches one issued report through a share link, under the agreement you attached to it. No other project, no team, no settings, and nothing behind the report.

Outside readers

A reader accepts your terms before the first page renders

Sharing an issued report outside the project happens under agreements you set, and the record of who accepted what is kept as evidence.

The gate

Confidentiality and non-reliance agreements are accepted before any content loads, and the check runs at the one point every share-scoped request passes through, so no route can serve a page around it. On the upper plans the wording is your own, and a negotiated reliance letter is recorded as an executed instrument: the reader sees its date and liability cap on every visit, and a lapsed letter closes the gate.

The ledger

Each acceptance or decline is stored with the person, the agreement version, a hash of the exact text, the time, the network address and the browser. The reader receives a copy of what they accepted by email, and the ledger for a project downloads as a CSV for the deal file.

On every page

A ribbon the reader cannot dismiss states their posture, and a repeated watermark carries their identity. Printing, Save as PDF included, produces a single notice sheet instead of the report. A determined reader can still take a screenshot. This closes the easy copy, not the impossible one.

Links and versions

An invitation link is single-use, lives 14 days and is stored only as a hash, so it cannot be replayed once claimed. Every recipient is named on the version they can open, with the state of the invitation, expired included. When someone can still open a superseded issue a banner says so, and one confirmation closes it. A withdrawn version stays in the history with its reason.

Documents and models

Where your material is processed

Where the models run

Depending on how you are deployed, analysis runs on infrastructure we operate or routes to hosted model providers. We state which providers a deployment uses, in writing, on request — the terms say the same — and your documents are never used to train models.

No third-party analytics inside the product

Usage is measured in our own database. No analytics or advertising script loads on a page showing your material, and what is recorded is identifiers and counts: that a document was indexed and how many passages it produced, never its name, the project's name or a search query. The public site is separate, asks first where consent is required and offers a one-click opt-out everywhere.

Encrypted in transit and at rest

TLS at every public edge. Inside, services talk over a private network with no publicly routable ports, and stored files and derived data are encrypted at rest.

Your own agents

An agent you connect uses a model you chose and operate. Its key is scoped to one project with read, write or research permission, stored only as a hash, expires after 90 days unless you set a longer life (a year at most), and can be revoked at any time. Every call is attributed to the person who minted it.

Deletion reaches the index

Removing a document withdraws it from search before the row is dropped, and a deleted file turning up in search is a case we test for. Ask for a documented deletion and support confirms what was removed and when.

Support does not read your documents

Support can see a workspace's structure, its runs and its errors. Nobody opens a project document to answer a ticket unless you name one, and we say so when we do. Tickets are answered within one business day.

In writing

The terms make your documents, findings and reports Confidential Information: used only to provide the service, disclosed only to providers bound in writing, never training data, deleted on termination. A countersignable Confidentiality Addendum is available from your Legal settings for a counterparty who needs us bound on paper.

Signing in, and the record of it

  • A password and a one-time code from an authenticator app. Recovery codes are shown once, stored as hashes and spent on use.
  • Turning two-factor off asks for a current code, so a stolen session is not enough to strip it.
  • Microsoft Entra ID where the deployment enables it, with multi-factor enforced by the identity provider and new accounts created only from allowed domains.
  • Five sign-in attempts a minute from one address. Tenant selection completes with a single-use signed token.
  • An activity record of sign-in, tenant selection, agreement acceptance, sharing decisions and administrative changes.

Outbound connections

What leaves the platform

A questionnaire will ask what connects outward from a project, and when. This is the whole list.

  • Private source code

    Never

    The target’s engineers run the extractor inside their own network and hand your team the bundle: commit history, authorship, file and language distribution, dependency manifests. We hold no credentials to any source host.

  • A public repository

    When you paste its URL

    One clone of that repository, made without credentials. A supplied credential is refused.

  • The open web

    Only when an analyst registers a page

    The analysis does not search the web. A page enters a project when an analyst adds it to the register, and it is fetched through the indexing service’s egress guard, which refuses private addresses. The public posture of a registered domain (DNS, TLS, HTTP headers) is read the same way.

  • Public package registries

    During source-code analysis

    Component names and versions from the components inventory, checked against public advisory and registry data. No document text.

  • A hosted model provider

    Where a deployment routes a workload there

    Document-derived text for that workload. We state which providers are in use, in writing, on request, and it is never used for training.

Percomb makes no other connection outward with your material.

When a project ends

Nothing is deleted because a plan changed

Procurement always asks this before it asks anything else. Here is what happens to the material.

Moving down a plan

Projects over the new limit become read-only. Issued report versions are retained. External shares that are live run to their expiry unless you revoke them.

Deleting

A document leaves the search index before its row is dropped. Deleting a project needs the permission to do so and removes its material. A documented deletion, confirming what was removed and when, is yours for the asking.

Closing the account

Ask support, and we confirm the deletion in writing. There is no bulk export of a workspace. A report lives at its link, where a correction reaches every reader, and it stays readable there.

Not claimed

What this page does not claim.

Three things a reviewer will ask about, and where we stand on each.

Certification

None completed, and we will not imply one. Ask and we will tell you where we are in the cycle, with dates.

Penetration testing

No test report is published here. If you need to see one before you upload, say so and we will discuss what we can show you.

Where your data sits

That depends on how you are deployed, and so does which models process it. Ask, and we put both in writing.