CoverProof

Procurement Bundle

Everything your IT and legal team needs to evaluate CoverProof — DDQ-style answers assembled from verified production facts, not marketing copy. Share this URL directly.

Last updated: 10 June 2026

Hosting and data residency

Source for every claim: Trust Centre sub-processor list. Contradictory copy on other marketing pages has been noted for correction.

QuestionAnswer
Where is the application hosted?Railway (United States). Railway provisions the Node.js application server and managed PostgreSQL database.
Where is primary data stored?PostgreSQL managed by Railway. The database server is in the United States.
Where are evidence-pack PDFs stored?Cloudflare R2 (configurable region — not yet restricted to EU/UK; the bucket jurisdiction has not been set to a specific region). PDFs are encrypted at rest.
What international-transfer safeguards apply?Data transfers to US processors (Railway, Anthropic, Resend, Stripe) are covered by UK GDPR Chapter V safeguards (Standard Contractual Clauses or equivalent adequacy). Details in the Data Processing Agreement.
Is data available from within the UK or EEA?The application is accessible from any jurisdiction. Data at rest resides in the United States. No EU/EEA-only storage option is currently offered.

Sub-processors

Full list at /trust. We will notify existing customers before adding a new sub-processor.

Sub-processorPurposeLocation
RailwayApplication hosting and managed PostgreSQL databaseUnited States
Cloudflare R2Encrypted PDF storageConfigurable region (not yet restricted)
AnthropicAI gap-classification (Claude API). Only role-function text is sent — no IRNs, no personal data.United States
ResendTransactional email (magic-links, declaration invites, reminders)United States
StripeSubscription billing and payment processingUnited States / UK
PostHogConsent-gated, IP-anonymised product analyticsEuropean Union

Coverage source trust

Coverage and benchmark pages use official FCA source channels and customer-provided firm records. Public aggregate context renders only when the source date range, methodology version, output hash prefix, and legal-safety caveat are complete. Low-count, missing-provenance, and stale-source inputs are suppressed instead of filled with marketing copy.

Buyer questionAnswer
Where do public coverage claims come from?They come from FCA register source data, internal coverage-asset rows derived from that source, and customer-provided firm records where the customer runs a check.
How are benchmark-style aggregates labelled?Every renderable aggregate stat must show source date range, methodology version, and output hash prefix. If those labels are missing or inconsistent, the public benchmark page suppresses the stat.
What should procurement not read into the data?The coverage asset is not FCA endorsement, not complete market coverage, not a market benchmark, and not a legal conclusion about any firm, role, or individual.

Inspect the public source controls: data moat and source posture, coverage data methodology, and coverage benchmark context.

Procurement export pack

This pack groups methodology, security, and evidence summaries for procurement review. It contains 3 sections and 13 public source links.

Methodology summary

Versioned methodology, promotion status, benchmark caveats, FAQ answers, and public claim-gate evidence for reviewer due diligence.

Security summary

Hosting, sub-processors, tenant isolation, audit controls, DPA, privacy, and security-questionnaire answers with honest certification status.

Evidence summary

Board evidence-pack contents, synthetic sample pack, public verifier context, admissibility caveats, and coverage-source methodology.

  • The export pack is an index of public review artefacts, not a signed customer reference.
  • Verifier links are generated per evidence pack at /verify/[firmId]/[hash]; the procurement page does not expose firm-specific verifier records.
  • Security certifications remain roadmap/not-started where marked and are not converted into badges.
  • Evidence-pack materials describe business-record provenance; courts and regulators decide weight and admissibility on the facts.

Procurement export pack summarizes methodology, security, and evidence artefacts only; it does not claim signed pilots, customer proof, partner proof, legal sign-off, legal certainty, statutory defence, safe harbour, certification, procurement approval, or court outcome.

Export pack uses public links, section labels, aggregate counts, and caveats only; customer names, partner names, pilot applicants, emails, firm-specific verifier records, source rows, tokens, IPs, user agents, quotes, contracts, and notes are excluded.

DPA and security dependency handoff

H18 and H7 remain explicit dependencies: 2 pending, 0 complete. The rows below show what can be shared today and what must not be claimed yet.

DependencyCurrent evidenceBlocked claimsNext human action
H18 · Sub-processor DPAs and DPIA sign-off
pending_human_signature
  • Trust Centre sub-processor list is published.
  • Data Processing Agreement route is published.
  • Procurement export pack links DPA, privacy, trust, and security artefacts.
  • sub-processor DPAs fully countersigned
  • DPIA signed off
  • enterprise procurement complete
Collect sub-processor DPA evidence and complete DPIA sign-off before marking H18 complete.
H7 · Cyber Essentials, SOC 2, ISO 27001, and pen-test path
roadmap_not_started
  • Trust Centre lists certification roadmap honestly.
  • Security questionnaire marks Cyber Essentials, SOC 2, ISO 27001, and penetration test as not yet held.
  • Procurement bundle states no badge, no audit, and no independent penetration test has been completed.
  • Cyber Essentials achieved
  • SOC 2 certified
  • ISO 27001 certified
  • independent penetration test completed
Purchase/complete certification or assessment work before changing public badges or questionnaire status.

Dependency handoff surfaces H18 and H7 pending states only; it does not claim countersigned sub-processor DPAs, DPIA sign-off, Cyber Essentials, SOC 2, ISO 27001, completed penetration test, enterprise procurement approval, or security certification.

Dependency handoff uses gate ids, dependency labels, public source labels, and next actions only; customer names, sub-processor contracts, DPA drafts, DPIA working papers, emails, signatures, tokens, IPs, user agents, and notes are excluded.

Access control and tenant isolation

QuestionAnswer
How is tenant data isolated?PostgreSQL Row-Level Security (RLS) with FORCE ROW LEVEL SECURITY on every business table. A database query can only return rows belonging to the authenticated firm — even a bug in application-layer filtering cannot expose another tenant's data. See /security for the full technical description.
What database role does the application use?A dedicated coverproof_app role with NOSUPERUSER and NOBYPASSRLS. The superuser connection is kept separate for schema migrations only.
Is the audit log append-only?Yes. The audit_events table grants UPDATE/DELETE to no role — only INSERT is permitted for the application role. Verified by production database inspection.
How is authentication handled?Magic-link email + optional password, via Better Auth. Sessions are short-lived (httpOnly cookie). Multi-factor authentication is not yet supported.
Does CoverProof personnel have access to my firm's data?Only for support purposes and only with explicit consent. No data is sold or used for model training.

AI use and boundaries

AI-assisted classification — constrained to a fixed verdict schema. Compliance officer review required before declarations.

QuestionAnswer
What data is sent to Anthropic (Claude API)?Only the individual's functional role description as submitted by the firm. FCA Individual Reference Numbers (IRNs), names, email addresses, and other personal data are not sent to the Claude API.
Is output deterministic?Temperature is set to 0. The same input returns the same verdict. The methodology version is pinned and logged with every classification.
Is the AI output audited?Yes. Every classification records the prompt, raw response, model ID, and methodology version in the database audit trail.
Can AI output be overridden?Yes. A compliance officer must review every classification before declarations are sent. The platform enforces this workflow — it does not automate the send.
Is AI output used to train Anthropic models?No. Anthropic's API terms prohibit training on customer API calls by default. CoverProof does not opt in to any model-improvement programme.

Data retention

Data typeRetention
Active subscription data (declarations, gap analyses, evidence packs)Held for the duration of the subscription plus 30 days post-cancellation.
Data after cancellation (30-day window)Accessible to export for 30 days after cancellation, then securely deleted.
Audit eventsRetained for the life of the subscription. Append-only; cannot be modified or deleted by application code.
Evidence-pack PDFs (Cloudflare R2)Retained for the subscription period. Deleted on account closure.
Analytics (PostHog)Consent-gated, IP-anonymised. Retention follows PostHog's EU-hosted data policy.

Full retention terms in the Data Processing Agreement and the Privacy Policy.

Certifications — current status, not a claim

CoverProof holds no third-party security certification today. The table below is a forward-looking roadmap. We do not display a badge we have not earned.

ProgrammeStatus
Cyber EssentialsNot started — no application submitted, no badge held.
Independent penetration testPlanned — not yet commissioned.
SOC 2 Type IIRoadmap — not started.
ISO/IEC 27001Roadmap — not started.

Key documents for your team

To request a countersigned DPA or a custom security questionnaire response, email hello@coverproof.co.uk with “Procurement pack request” in the subject line.