Security questionnaire
The questions vendor assessments ask, answered in advance so a consultant can hand this over without waiting on us. Where the honest answer is no, it says no.
Last updated 1 September 2026
How to use this page
This covers the standard set. If a client's questionnaire asks something not answered here, send it to security@personalobby.ie and we will respond within five working days. See also the data processing agreement and the sub-processor list.
Company and service
- Who operates the service?
- Probity Net Limited, registered in Ireland, trading as Outweigh.
- What does the platform do with customer data?
- It stores the decisions a customer brings, the material they upload, and the councils, briefs, reports and decision records generated from them, and keeps that history available to their workspace.
- Is the service multi-tenant?
- Yes. Every customer organisation has its own workspace within a shared platform.
Hosting and infrastructure
- Where is data hosted?
- The database and file storage are hosted in Ireland (AWS eu-west-1). The application is served from Cloudflare's edge network.
- Who are the sub-processors?
- Published in full, with purpose and location, on the sub-processors page. Additions are published and notified before they begin processing.
- Is data transferred outside the EEA?
- Stored data remains in Ireland. Content is sent to language-model providers at the moment an output is generated; some of those providers process in the United States under Standard Contractual Clauses.
Isolation and access control
- How is one customer's data separated from another's?
- Row-level security policies in the database restrict every row to the organisation that owns it. Separation is enforced by the database itself, not only by application code.
- Is that isolation tested?
- Yes. An automated suite provisions throwaway organisations and users, then attempts cross-organisation reads, updates, deletes and inserts across every user-facing table, plus search, assistant and storage paths. Any success fails the build. The most recent run completed 63 checks with 0 failures; the dated report is available on request.
- How are users authenticated?
- Email and password, or Google sign-in. Sessions are issued by the authentication provider; passwords are stored as one-way hashes and are not recoverable by us.
- Is multi-factor authentication available?
- Not natively in the platform today. Customers using Google sign-in inherit whatever multi-factor policy their Google Workspace enforces. Native MFA is on the roadmap and is not claimed as available.
- How is authorisation decided?
- Every server call derives identity and organisation membership from the verified session, never from values supplied by the browser. Roles determine what a member can do within their organisation.
- Is there single sign-on?
- Google sign-in is supported. SAML SSO is not available today.
Encryption
- Is data encrypted in transit?
- Yes, TLS on all connections.
- Is data encrypted at rest?
- Yes, by the infrastructure provider, at the disk and storage layer.
- Is data encrypted at field level, or with customer-managed keys?
- No. Decision content is stored as readable text so the platform can search it and generate outputs from it. Customer-managed keys are not offered today.
- Can the vendor read customer content?
- Personnel with infrastructure credentials are technically capable of reading it. The controls against that are least privilege, access logging visible to the customer, confidentiality obligations and the data processing agreement — not cryptography. We state this plainly rather than imply otherwise.
Logging and monitoring
- Is administrative access logged?
- Yes. Platform-administrator access to an organisation's workspace is role-gated and written to an audit record that the customer's own owner can view in their settings.
- Are application and infrastructure logs kept?
- Yes, operational logs needed to run, secure and debug the service, retained by the infrastructure provider on its standard cycle.
- Is there 24/7 security monitoring or a SIEM?
- No. We rely on the infrastructure provider's platform monitoring. We do not claim a staffed security operations capability.
Backups, availability and continuity
- Are backups taken?
- Yes, by the managed database provider on its standard schedule, stored in the same EU region.
- Is there a documented disaster recovery plan with tested RTO and RPO?
- No formal tested plan exists today. Recovery relies on the provider's managed backups and redeployment of the application. We do not quote an RTO or RPO we have not tested.
- Is there an uptime commitment?
- No contractual SLA is offered by default. Enterprise agreements can include one.
Data retention and deletion
- How long is data retained?
- For as long as the workspace is active.
- How is deletion handled?
- On written request we delete the workspace and its contents and confirm in writing. Backups containing deleted data expire within thirty days.
- Can a customer export their data?
- Yes. Decision records, briefs and reports are viewable and exportable from the workspace, and a full export can be requested.
Artificial intelligence
- Which AI providers receive customer content?
- Google and OpenAI models, routed through the Lovable AI gateway. Named on the sub-processors page.
- Is customer content used to train models?
- No. Content is sent for inference only and is not used to train general-purpose models.
- Can the assistant reach another organisation's data?
- No. Retrieval is scoped server-side to the organisation the signed-in user is working in, and the scope is validated on the server rather than trusted from the browser.
- Are AI outputs presented as research findings?
- No. Outputs are decision support: interpretations grounded in supplied evidence, labelled as such, and distinguished in the product from observed outcomes.
Incidents, testing and certification
- Has the service had a security breach?
- No personal data breach has occurred to date.
- What is the breach notification commitment?
- Notification to the affected customer within 48 hours of becoming aware, as set out in the data processing agreement.
- Has an independent penetration test been carried out?
- No. Isolation is covered by the automated test suite described above; no third-party penetration test has been commissioned.
- Do you hold SOC 2, ISO 27001 or HIPAA certification?
- No, and none is in progress. We do not claim, imply or plan to imply certification we do not hold.
- Is there a vulnerability disclosure process?
- Yes. Report to security@personalobby.ie; we acknowledge within three working days.