The packet your IT review asks for.
Implemented claims below point to repository evidence or a regulatory source; target-state controls are labeled as targets. The visible demo uses synthetic fixtures by default, and the documents declare what does not exist yet. Where counsel, institutional, or independent review is pending, the document says so.
Looking for the short version? The Security page is the one-screen summary; this is the full packet.
Start here
Privacy & data
Security controls
A current-versus-target safeguards map covering risk assessment, access, encryption, monitoring, response, and open work.
Demo roles, current tenant controls, and the additional provisioning and access evidence a production pilot requires.
Which actions require staff judgment or sign-off, which bounded paths may be configured, and where the current demo stops.
Severity levels, notification clocks, and who is on the hook when something goes wrong.
Vendor assessment
Signed in? The Guardrails pagerenders the allowed-and-prohibited matrix live against your institution's actual settings.