Trust center · Last reviewed August 2026

Meaning is only useful when the context is protected.

This page distinguishes implemented website controls, public-demo restrictions and customer-project security choices. SDS does not claim third-party certifications that have not been independently evidenced.

Website and public demo

Designed for data minimization.

The public Foundry processes small samples in the browser and does not intentionally upload the dataset to SDS.

PUBLIC DEMO

Non-sensitive examples only

Do not use personal, confidential, regulated, proprietary, material non-public or trading-sensitive information. Use built-in synthetic samples where possible.

TRANSPORT

HTTPS required in production

Deploy behind Hostinger TLS. Security headers deny framing, restrict browser capabilities and reduce content-type ambiguity.

AUTHENTICATION

Protected author workspace

Administrator passwords use PHP secure password hashing. Sessions use HTTP-only, SameSite cookies and regenerate after login.

APPLICATION

Validated state changes

Content and consultation actions use server-side validation, CSRF tokens, limits and protected JSON storage in the shared-hosting edition.

FILES

Controlled demo input

The Foundry accepts only small CSV and JSON examples, checks extension and size, reads locally and never executes uploaded content.

RETENTION

Minimal lead records

Consultation and optional assessment submissions store business contact details and context for follow-up. Operators should periodically export and remove records no longer needed.

Customer deployment choices

Security follows the data classification.

AreaSDS project principleDecision evidence
AccessLeast privilege, role and purpose contextAccess model and reviewed authorization tests
LineageRetain source, mapping, transformation and rule provenanceTraceable evidence path
DeploymentCustomer cloud, private environment or approved managed platformArchitecture and responsibility matrix
Backup & recoveryVersioned artifacts and tested recovery matched to criticalityRecovery procedure and test record
Vulnerability managementDependency, configuration and code review appropriate to the stackFindings, ownership and remediation status
Third partiesDisclose providers and minimize data transferVendor inventory and processing purpose
Responsible AI principles

AI should inherit governed context.

Trace evidence

Keep source, entity, relationship, rule and model context available for review.

Respect authorization

Retrieval and agent actions should honor purpose, sensitivity and access boundaries.

Evaluate by decision

Test groundedness, completeness and harm against real competency questions—not a universal accuracy claim.

To request current security documentation or discuss a private deployment, contact info@semanticdataservices.com.