Trust and security

Evidence is useful only when its boundaries are honest.

These are product controls implemented in the current build. They are not a certification, penetration-test report, or promise that every government portal is supported.

Tenant separation

Every customer record is company-scoped. Database row-level security and controlled operations are tested against cross-company access.

Private evidence

Uploads, exports, and evidence reports use private storage and expiring access. Public links are not used for customer tax documents.

Credential boundary

Supervised portal discovery keeps login and MFA under customer control. Checkfiled does not ask a customer to send a portal password.

Human-reviewed AI

Document extraction produces cited proposals. A person accepts or corrects fields before they become filing evidence.

Fail-closed status

Only explicit accepted authority evidence can become verified. Stale, missing, unknown, received, rejected, and simulated evidence cannot appear green.

Lifecycle controls

Owners can export company data, revoke sessions and invitations, communicate incidents, and request deletion through a cooling-off process.

Before production: Checkfiled still requires a hosted restore drill, authenticated browser/accessibility testing, incident rehearsal, and an authorized repeat run for the first real authority adapter.