Skip to content
Trust Center

Security, independence, and what we read from your systems.

This page describes the controls in the product today. We do not display certifications or customer names here; ask us for current documentation through the contact page.

Tenant isolation

Every row is scoped to a tenant ID derived from the session token, enforced in the API layer and by database-level row filters. There is no cross-tenant query path in the product.

Secrets

Connector credentials are encrypted at rest with per-tenant keys and never returned by the API after creation. API keys and webhook secrets are shown once. The browser never holds a bearer token; it is kept in an httpOnly cookie and attached server-side.

Data minimisation

Connectors pull only the fields listed below. Message bodies are not stored unless transcript assist is explicitly enabled, and then only as redacted excerpts for sampled claims.

Audit log

Every sign-in, settings change, statement share, counterparty view and export is recorded with actor, IP and timestamp and can be exported as CSV.

Evidence integrity

Verdicts are SHA-256 hashed and chained. Statement and dispute-package hashes are publicly verifiable without an account.

Retention and deletion

Retention is configurable per tenant. A data deletion request is acknowledged with a receipt ID and completed within the retention SLA in your agreement.

Least-privilege scopes

Exactly which scopes each connector asks for.

Loaded from the live connector catalog. Every scope is read-only.

The connector catalog could not be loaded from the API right now.

Sign in to continue

Refresh the page to try again.

Independence policy

Paid by customers only.

CommitLayer is paid exclusively by the customers whose invoices it verifies. To keep verdicts credible to both sides of an invoice:

  • We do not accept payment, referral fees, revenue share, equity or sponsorship from any vendor whose claims we verify.
  • We do not sell, license or share verification data with vendors. A vendor sees only what a customer explicitly shares, as a watermarked, audit-logged view.
  • Vendor definitions in the library are transcribed from public documentation and cited. Vendors may submit corrections with a link to current documentation; corrections are recorded as new contract versions with a visible diff.
  • Verdicts are produced by deterministic rules. No person or model overrides a verdict; if a rule is wrong, the contract is versioned and the statement regenerated.
  • Employees may not hold positions that would conflict with this policy; procedures are available on request.

Questions about this policy can be sent through the contact page.