Trust centre
Everything a client's procurement or data protection team needs, in one place. We state what is implemented and what is not. We make no certification or audit claims.
Last updated 1 September 2026
Documents
The short version
- Isolation — every organisation's work is separated at the database level with row-level security, not only in application code.
- Tested, not asserted — an automated suite attempts cross-organisation reads and writes across every user-facing table and fails the build if any succeed. The most recent run completed 63 checks with 0 failures.
- EU hosting — the database and file storage are hosted in Ireland (AWS eu-west-1) and encrypted at rest. All traffic is served over TLS.
- Private files — uploads are stored in private buckets and served only through short-lived signed links.
- No model training — your decision content is not used to train general-purpose models.
- A DPA you can sign — our standard Article 28 terms are published, not negotiated from scratch each time.
What we do not claim
Outweigh holds no SOC 2, ISO 27001 or HIPAA certification or attestation, and none is in progress. Decision content is stored as readable text so that the platform can search it, generate councils and write reports; it is protected by isolation, least privilege, access logging and contract — not by cryptography that would make it unreadable to us. If a client requires cryptographic separation from the operator, tell us before signing and we will discuss what is realistic.
Contact
Security questions and vulnerability reports: security@personalobby.ie. Data protection and DPA requests: hello@personalobby.ie.