Not yet built
Managed sign-in activation, invitation delivery, real provider connections and webhooks, production backups and alerting, and white-label domains with live DNS or TLS.
Loading this page.
SECURITY AND DATA
This page describes how the system is built. It is not a certification, an audit report or a security guarantee, and it does not claim to be one. Most of what a system like this gets wrong is a boundary in the wrong place, so these are the boundaries, in the order they matter, followed by what has not been done yet.
THE SHORT VERSION
One business cannot reach another. A role reaches less than the base role it came from, never more. And a definition, a submission and a verified result are stored as three different records, so none of them can be mistaken for another.
The rest of this page is the detail behind those three sentences, and then an honest list of what has not been built or independently checked.
Records are tenant separated, and a reference to a record is qualified by the business it belongs to rather than trusted on its own. A role title is not a permission. On every write the server rechecks the session, the active membership, the selected business, the portal the request came through, the CSRF token and the revision of the record being changed, and it does that inside the write transaction rather than before it, so a permission that changed a moment ago cannot be used by a request that started a moment earlier.
Owners and Admins install templates and assign work. Managers review their own business’s work. Members see and submit their own assigned work, training and evidence, and not another member’s. A custom role only ever subtracts from the base role it is built on; there is no mechanism by which one adds. A draft role grants nothing at all: access follows only from a reviewed, published version pinned to a named person. Where a business has restricted per-person cost visibility, that restriction is stored separately so an unrelated change cannot quietly erase it.
What a process says should happen, what somebody submitted, and what was independently verified are stored as separate things. A saved record is not a finished task and a finished task is not a business result, so none of the three can be read as another. Assignments are pinned to a template version, and a template upgrade requires explicit review rather than arriving on its own: existing assignments keep the version their instructions and proof requirements were pinned to. Archiving preserves history instead of removing it.
A service that has not been connected is labelled as not connected rather than shown as working, and a placeholder cannot be activated by pasting a key into it. Real provider connections and webhooks are not finished. Managed sign-in has been built and tested in isolation and is not connected in production, so password sign-in remains the retained route. This site says the same thing in the same words everywhere it comes up, because a status that is optimistic in the marketing copy and accurate in the release notes is a status nobody can use.
The contact form validates the fields it declares, caps the length of a message, normalises the email address and carries a stable retry identifier so a resubmitted enquiry is not recorded twice. Fields it did not ask for are dropped rather than refused, because telling a prober which names are real is a favour to nobody, and submissions are rate limited per address. Where business information is projected onto a public page it is allowlisted field by field and carries no credentials. Sign-in holds a small number of concurrent operations per process with no queue, and returns a generic error under load rather than a message that describes the system.
WHAT IS NOT DONE
A security page that only lists strengths is a sales page. These are the gaps as they stand, and they are the same gaps named in the product status on the home page.
Managed sign-in activation, invitation delivery, real provider connections and webhooks, production backups and alerting, and white-label domains with live DNS or TLS.
No external security review, penetration test or accessibility audit has been completed. Assistive-technology and human usability testing remain outstanding.
Nothing on this page is a certification, an audit report or an assurance standard. two7 holds none, and claims none. This is a description of how the system is built, offered so that a reader can ask a sharper question.
RAISING SOMETHING
Email hello@two7.ai, or use the contact form. Please do not send passwords, payment details, API keys or customer records through either one. If you are reporting something you believe is a vulnerability, describe it in general terms first and we will agree a safer route for the detail.
Contact two7What the website collects →