TRUST CENTRE

Built so your evidence holds up.

Conectir handles sensitive investigation material, so data protection is built into the architecture — not bolted on. Here's what's in place today and what's on the roadmap, stated plainly.

IN PLACE TODAY

How your case data is protected.

Encrypted in transit and at rest

Case data is encrypted in transit (TLS) and at rest (AES-256), database backups included.

Never used to train AI

SCAN, timeline analysis and the AI Advisor send your case material to the AI only at the moment of analysis — and it is never used to train AI models.

Per-user access control

Row-level security means each user can only ever reach their own cases. Uploaded evidence is held in private storage, not on public URLs.

Passwords are never stored

We never keep your actual password — only a one-way, salted bcrypt hash (a scrambled fingerprint that can't be reversed). When you log in, the fingerprint is re-computed and compared, so even we can't see your password and a database breach can't reveal it. Email magic-link sign-in and two-factor backup codes are also supported.

Tamper-evident evidence vault

Every file is fingerprinted (SHA-256) the moment it is uploaded, and that fingerprint is locked into the case's hash-chained audit trail at the same moment — so the record of what entered the vault can't be quietly rewritten later. One click re-verifies any exhibit: the stored bytes are re-hashed and compared with the upload fingerprint, match or mismatch, and the check itself lands on the trail. Integrity you can demonstrate, not just assert.

Court-ready audit trail

Every meaningful action on a case is recorded on a hash-chained, timestamped audit log written by the database itself — append-only, tamper-evident, and printed as a report appendix, so the chain of custody holds.

Stored in the EU

Case data is stored in the European Union (Ireland), within EU jurisdiction — encrypted and access-controlled. (AI analysis is processed by our providers under transfer safeguards; EU-only processing is available to Enterprise customers on request.)

SECURITY OPERATIONS

How we run, honestly.

A live status page, an open door for security researchers, and an independent penetration test before launch — stated as it is, not as we'd like it to look.

Status & uptime

All systems operational. Uptime is monitored live by an independent third party.

status.conectir.com →

Vulnerability disclosure

Coordinated disclosure is welcome, with safe harbour for good-faith security research.

security@conectir.com

Penetration testing

An independent external penetration test is scheduled before launch. The summary is shared with customers under NDA once it's complete.

COMPLIANCE

Where we are, honestly.

We don't claim certifications we don't hold. These are in progress — we'll update this page as each milestone lands.

GDPR & UK GDPR

In progress

Building toward lawful-basis tagging and data-subject export.

POPIA

In progress

Operator-agreement-ready; Information Regulator alignment underway.

CJIS Security Policy (FBI)

Aligned

Our controls are mapped to the FBI's CJIS Security Policy v6.0 — the US standard for protecting criminal justice information. Aligned, not certified (there is no CJIS certification); the full alignment statement is available to customers on request.

LEGAL DOCUMENTS

Every policy, in one place.

The documents that govern how Conectir handles your data and your account. Each opens in full.

DOCUMENTS

Sub-processors, DPA and the trust pack.

Our list of sub-processors is published and kept current. A Data Processing Agreement (DPA), CJIS alignment statement, security questionnaire and full trust pack are available to customers on request.