Trust

Security questionnaire

The questions vendor assessments ask, answered in advance so a consultant can hand this over without waiting on us. Where the honest answer is no, it says no.

Last updated 1 September 2026

How to use this page

This covers the standard set. If a client's questionnaire asks something not answered here, send it to security@personalobby.ie and we will respond within five working days. See also the data processing agreement and the sub-processor list.

Company and service

Who operates the service?
Probity Net Limited, registered in Ireland, trading as Outweigh.
What does the platform do with customer data?
It stores the decisions a customer brings, the material they upload, and the councils, briefs, reports and decision records generated from them, and keeps that history available to their workspace.
Is the service multi-tenant?
Yes. Every customer organisation has its own workspace within a shared platform.

Hosting and infrastructure

Where is data hosted?
The database and file storage are hosted in Ireland (AWS eu-west-1). The application is served from Cloudflare's edge network.
Who are the sub-processors?
Published in full, with purpose and location, on the sub-processors page. Additions are published and notified before they begin processing.
Is data transferred outside the EEA?
Stored data remains in Ireland. Content is sent to language-model providers at the moment an output is generated; some of those providers process in the United States under Standard Contractual Clauses.

Isolation and access control

How is one customer's data separated from another's?
Row-level security policies in the database restrict every row to the organisation that owns it. Separation is enforced by the database itself, not only by application code.
Is that isolation tested?
Yes. An automated suite provisions throwaway organisations and users, then attempts cross-organisation reads, updates, deletes and inserts across every user-facing table, plus search, assistant and storage paths. Any success fails the build. The most recent run completed 63 checks with 0 failures; the dated report is available on request.
How are users authenticated?
Email and password, or Google sign-in. Sessions are issued by the authentication provider; passwords are stored as one-way hashes and are not recoverable by us.
Is multi-factor authentication available?
Not natively in the platform today. Customers using Google sign-in inherit whatever multi-factor policy their Google Workspace enforces. Native MFA is on the roadmap and is not claimed as available.
How is authorisation decided?
Every server call derives identity and organisation membership from the verified session, never from values supplied by the browser. Roles determine what a member can do within their organisation.
Is there single sign-on?
Google sign-in is supported. SAML SSO is not available today.

Encryption

Is data encrypted in transit?
Yes, TLS on all connections.
Is data encrypted at rest?
Yes, by the infrastructure provider, at the disk and storage layer.
Is data encrypted at field level, or with customer-managed keys?
No. Decision content is stored as readable text so the platform can search it and generate outputs from it. Customer-managed keys are not offered today.
Can the vendor read customer content?
Personnel with infrastructure credentials are technically capable of reading it. The controls against that are least privilege, access logging visible to the customer, confidentiality obligations and the data processing agreement — not cryptography. We state this plainly rather than imply otherwise.

Logging and monitoring

Is administrative access logged?
Yes. Platform-administrator access to an organisation's workspace is role-gated and written to an audit record that the customer's own owner can view in their settings.
Are application and infrastructure logs kept?
Yes, operational logs needed to run, secure and debug the service, retained by the infrastructure provider on its standard cycle.
Is there 24/7 security monitoring or a SIEM?
No. We rely on the infrastructure provider's platform monitoring. We do not claim a staffed security operations capability.

Backups, availability and continuity

Are backups taken?
Yes, by the managed database provider on its standard schedule, stored in the same EU region.
Is there a documented disaster recovery plan with tested RTO and RPO?
No formal tested plan exists today. Recovery relies on the provider's managed backups and redeployment of the application. We do not quote an RTO or RPO we have not tested.
Is there an uptime commitment?
No contractual SLA is offered by default. Enterprise agreements can include one.

Data retention and deletion

How long is data retained?
For as long as the workspace is active.
How is deletion handled?
On written request we delete the workspace and its contents and confirm in writing. Backups containing deleted data expire within thirty days.
Can a customer export their data?
Yes. Decision records, briefs and reports are viewable and exportable from the workspace, and a full export can be requested.

Artificial intelligence

Which AI providers receive customer content?
Google and OpenAI models, routed through the Lovable AI gateway. Named on the sub-processors page.
Is customer content used to train models?
No. Content is sent for inference only and is not used to train general-purpose models.
Can the assistant reach another organisation's data?
No. Retrieval is scoped server-side to the organisation the signed-in user is working in, and the scope is validated on the server rather than trusted from the browser.
Are AI outputs presented as research findings?
No. Outputs are decision support: interpretations grounded in supplied evidence, labelled as such, and distinguished in the product from observed outcomes.

Incidents, testing and certification

Has the service had a security breach?
No personal data breach has occurred to date.
What is the breach notification commitment?
Notification to the affected customer within 48 hours of becoming aware, as set out in the data processing agreement.
Has an independent penetration test been carried out?
No. Isolation is covered by the automated test suite described above; no third-party penetration test has been commissioned.
Do you hold SOC 2, ISO 27001 or HIPAA certification?
No, and none is in progress. We do not claim, imply or plan to imply certification we do not hold.
Is there a vulnerability disclosure process?
Yes. Report to security@personalobby.ie; we acknowledge within three working days.