Search all 586 artefacts by title, document ID or content.
Policy | Family 15, Trust Center Meta
To decide, repeatably, what tier a document is published at, who approves publication, and what must be true before a document appears on the Trust Center at all.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
To decide, repeatably, what tier a document is published at, who approves publication, and what must be true before a document appears on the Trust Center at all.
A document is gated unless one of the following is positively true of it. Each is a positive finding, recorded against the document, and the finding is what places a document in the public tier. The absence of a reason to gate is not a finding and does not make a document public.
| Test | If true, tier |
|---|---|
| The law requires the document to be available to anyone: a privacy notice, a cookie and consent notice, a grievance officer notice, a data principal rights channel, a vulnerability disclosure address published under RFC 9116, an accessibility statement | T_PUBLIC |
| The document is addressed to a person who can never hold a credential: a patient, a member of hospital staff who is not a Customer contact, a job applicant, an unsolicited security researcher | T_PUBLIC |
| The document binds a visitor who has signed nothing, or is itself the instrument of the gate: the site and Trust Center terms, the click-through NDA, this policy, the access request form | T_PUBLIC |
The document is the entry point a reviewer needs before they can tell what to request: who Edsol Edtech Pvt. Ltd. is, what assurance does and does not exist, and the regulatory boundary of the product |
T_PUBLIC |
| None of the above | Gated. Clause 1.6 sets which gate |
1.1 The public tier is short by design, and the openness is delivered as latency. A hospital cannot
evaluate what it cannot read, and an unknown vendor cannot afford to be coy. Pensieve Labs answers
that with a gate that opens in hours and never asks a sales question, and not with an open estate that
serves contract templates, internal control policies and assurance evidence to anyone who arrives without
saying who they are. The security whitepaper, the architecture overview, the sub-processor register, the
DPA, the SLA, the standard MSA, the control policy set, the framework mappings and the assurance evidence
are T_NDA: one click, an administrator grant, a four business hour target, and the latency printed on
the lock. What used to be published is not withheld. It is dated, watermarked, and traceable to the
person who asked for it, which is what makes it safe to hand over the sensitive parts at all.
1.2 No certification claims. Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001, SOC 2, HITRUST, CE or ARTG
certification. No document may be published that states or implies otherwise. The Trust Center carries an
Assurance & Evidence section, not a Certifications section. Where a control set is mapped to a standard,
the correct form is: "controls are mapped to ISO/IEC 27001:2022 Annex A. Edsol Edtech Pvt. Ltd. is not
certified to ISO/IEC 27001. The Statement of Applicability is published at …"
1.3 Nothing is published that has not been reviewed for the presence of another customer's information.
A single hospital's name in a screenshot, log excerpt, sample report or example is a breach of
confidentiality and of MSA-IN-001 clause 12. Examples use obviously fictional names.
1.4 Redaction is a version, not an edit. Where a T_NDA document has a publishable summary, the summary
is a separate document with its own doc_id, its own tier and its own review date. A document is never
served in two different forms from one identifier.
1.5 The public list, in full. The table below is the list, and no others. It carries twenty-one rows
and twenty-two document identifiers, because POL-GL-500 and POL-GL-501 are one instrument published
under two identifiers. The register must therefore show exactly twenty-two T_PUBLIC records. The
Founder performs that reconciliation, at each review of this Policy under POL-GL-502 clause 1.2, which
is twelve months for a K_POLICY, and on any trigger at POL-GL-502 clause 1.7, and records the count
found in the change history below. Where a source file carries contains_doc_ids, every identifier in it
is tested against this clause separately: one frontmatter tier emitting two register records is the control
failure that published FRM-GL-509 unexamined. A document joins this list only by an amendment to this
clause, approved by the Founder under Section 2 and recorded. A document that no longer satisfies the
finding beside it leaves the list at the next review under POL-GL-502.
1.5.1 An application is not an admission. Several instruments across the estate record an amendment to this clause as a dependency of their own, in a dependency ledger or an equivalent table, and state that they are gated until it is made. Such a row is an application, not an amendment. It does not place the document on the list, it does not change the document's register record, and it is never read as making the document public. The list is only what the table below carries, and the only evidence that a document has joined it is a row in that table together with a change-history row recording the Founder's approval under Section 2. An author who finds a ledger row asserting that a document has been admitted must check the table; where the table does not carry the document, the document is not public and the ledger row is the thing that is wrong.
| Document | The finding that makes it public |
|---|---|
POL-GL-053 Privacy Policy |
Required by law to be available to anyone |
POL-GL-054 Cookie Policy and Consent Notice |
Required by law; the consent banner links to it |
NTC-GL-023 Notice to the Data Principal at the Point of Collection |
Must be readable at the moment of collection |
FRM-GL-505 Data Principal Rights Request Form |
A rights channel cannot itself be gated |
POL-GL-066 Grievance Redressal Policy and Grievance Officer Notice |
The grievance officer must be findable without a credential |
POL-GL-059 Vulnerability Disclosure Policy and security.txt |
RFC 9116 requires a public well-known address |
POL-GL-061 Accessibility Statement |
Required by law to be available to anyone |
POL-IN-320 Candidate and Recruitment Privacy Notice |
An applicant holds no credential, and a recruitment-fraud warning behind a gate warns nobody |
DIS-GL-037 Notice for Patients and Hospital Staff |
A patient can never sign an NDA |
POL-GL-051 Website Terms of Use |
Binds a visitor who has signed nothing |
POL-GL-052 Trust Center Terms of Use |
Binds a visitor who has signed nothing |
NDA-GL-002 Click-through Mutual Non-Disclosure Agreement |
Must be readable before it is accepted |
POL-GL-500 This policy, with POL-GL-501 |
A gate that will not explain itself is a dead end |
FRM-GL-504 Trust Center Request Access Form |
The entry point to everything else |
STM-GL-028 Company Profile and Corporate Overview |
Who the counterparty is |
WPR-GL-005 Trust and Assurance Overview |
What exists, what is coming, and what does not exist |
DIS-GL-028 Clinical Safety Boundary Statement |
A market-facing regulatory claim; gating it would read as evasion |
FRM-GL-509 Additional Credential Request |
A form that asks for a credential cannot itself require one. Published since first release inside the FRM-GL-504 source file, and recorded here rather than left off the list |
POL-EU-053 Privacy Policy, GDPR Variant |
Required by law to be available to anyone. POL-GL-053 states that it does not apply to a person in the EEA, so this is the only notice discharging Articles 12 to 14 of Regulation (EU) 2016/679 for an EEA reader |
POL-AU-053 Privacy Policy, Australia |
Required by law to be available to anyone. Australian Privacy Principle 1.4 requires the APP 1.3 policy to be available free of charge, and this document replaces Annexure B of POL-GL-053 for anyone in Australia |
STM-GL-037 Government Access and Lawful Requests Statement |
Required by law to be available to anyone. Regulation (EU) 2023/2854 Article 28(1) requires a provider of data processing services to make the jurisdiction of its ICT infrastructure and its anti-access measures available on its website, and Article 28(2) requires every contract to list that website |
1.6 Which gate a document sits behind. Applied only after the test at the head of this Section has returned gated. Each row is a positive finding, recorded against the document.
| Test | If true, tier |
|---|---|
| The document identifies a specific hospital, its commercials, its configuration or its people | T_CLIENT |
| The document is an internal operating instruction with no external audience and no evidential value | T_INTERNAL |
The document contains findings from an unremediated security test, internal hostnames, IP ranges, network topology at the level of DIS-GL-007, or anything that materially assists an attacker |
T_NDA |
| The document contains business-continuity test evidence, insurance policy wordings, or the full text of a third-party contract | T_NDA |
| The document's value is primarily as a lead magnet and its content is genuinely non-sensitive | T_EMAIL: used sparingly; the friction is real |
| None of the above | T_NDA |
1.7 T_NDA is the resting place of the estate, and that is deliberate. The clickwrap is the cheapest
gate that produces a named, dated, enforceable record of who holds the document. It is what lets
Pensieve Labs publish the sensitive material at all rather than write a thinner version of it. Where
a reviewer needs a document faster than the four business hour target, POL-GL-500 clause 1.5 domain
auto-approval exists precisely to take the administrator off the path.
| Step | Action | Owner |
|---|---|---|
| 1 | Draft authored against SPEC-005, with complete frontmatter | Author |
| 2 | Classification test at Section 1 applied; tier and the positive finding recorded | Author |
| 3 | Technical review: factual accuracy, per deployment model | Owning role |
| 4 | Legal review, only for statements creating liability, a certification implication, a medical claim, or a confidentiality breach | Legal |
| 5 | Publication approval | Founder for T_PUBLIC; owning role for all other tiers |
| 6 | review_due_on set; document registered; NTC-GL-020 entry queued |
System |
2.1 Legal does not decide whether to publish a security bulletin. NTC-GL-021 Section 11 governs.
2.2 Every published document carries, on every page: doc_id, version, Last Modified On, tier,
and, for the legal letterhead variant, the SHA-256 short hash and the verification QR resolving to
https://trust.pensievelabs.org/verify/. SPEC-003 Section D.2.
2.3 A document is never silently changed. A change of substance is a new version with a change-history row. A typographical correction is a patch version and is still recorded.
2.4 Withdrawal. A withdrawn document keeps its doc_id, is marked Withdrawn with the date and the
reason, and remains retrievable. Its successor is named. Trust centers that quietly delete documents are
the reason buyers take their own copies.
All security, legal, privacy and compliance copy on https://pensievelabs.org is served from the Trust
Center. The marketing site holds no separate copy and no separate version. Each document declares the
marketing paths it feeds in source_of_truth_for. A marketing page that restates a Trust Center fact in
its own words is a defect and is raised as one.
| Role | Accountable for |
|---|---|
| Author | Frontmatter, classification test, accuracy, no literals, deployment-model correctness |
| Owning role | Technical accuracy and the review date |
| Legal | Liability, certification implications, medical claims, confidentiality |
| Founder | T_PUBLIC publication approval, and every exception |
A document published at the wrong tier is re-tiered within 1 Business Day of discovery, the exposure is
assessed, and the event is recorded in the Incident Register (REG-GL-203) where anything at T_CLIENT or
above was exposed. Where another hospital's information was exposed, NTC-GL-002 applies.
| Topic | Document |
|---|---|
| Trust Center terms of use | POL-GL-052 |
| Click-through mutual NDA | NDA-GL-002 |
| Data classification (of customer data, not documents) | DIS-GL-022 |
| Document review and staleness | POL-GL-502 |
| Audit log retention | POL-GL-503 |
| Watermarking and leak tracing | POL-GL-510 |
| Access request and additional credential forms | FRM-GL-504, FRM-GL-509 |
| Access, refusal, revocation and cap e-mails | NTC-GL-505 to NTC-GL-508 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 2.2.0 | 29 August 2026 | Founder | Conforming pass on the closed list. No document's tier changes and no document joins or leaves the list. Every one of the twenty-one rows at clause 1.5, carrying twenty-two identifiers, was checked against the register on 29 August 2026. The register shows exactly twenty-two T_PUBLIC records and they are the same twenty-two identifiers, so the reconciliation clause 1.5 requires returns clean and no row is corrected. No amendment to this clause recorded elsewhere in the estate as landed was found missing from the table. Clause 1.5 previously required that reconciliation without naming who performs it or when; it now names the Founder, the twelve-month K_POLICY cadence at POL-GL-502 clause 1.2 and the event triggers at POL-GL-502 clause 1.7, and requires the count found to be recorded in this table. New clause 1.5.1 states that a row in another instrument's dependency ledger applying for admission to this clause is an application and not an amendment: it does not place the document on the list, does not change its register record, and is never read as making it public. Four such rows stand today and each is correct to describe its document as gated: POL-GL-074 clause 15.1 row D-8 and REG-GL-218 clause 7.4 row D-8, both for POL-GL-074; REP-GL-033 row A-1 for itself and row A-6 for POL-GL-074; and DIS-GL-823 clause 10.1.3 for REP-GL-033. Neither POL-GL-074 nor REP-GL-033 is admitted here. Admission is the Founder's decision under Section 2 on the positive findings at Section 1, it carries a register re-tier with it, and a conforming pass does not make it. |
| 2.1.0 | 29 August 2026 | Founder | Amends clause 1.5, the first amendment to the closed list. The list is restated as twenty-one rows and twenty-two document identifiers, counted separately because POL-GL-500 and POL-GL-501 are one instrument under two identifiers, and reconciled against the register at every review under POL-GL-502. Version 2.0.0 said seventeen documents while its table carried seventeen rows enumerating eighteen identifiers and the register carried nineteen T_PUBLIC records; the drift is corrected by counting rows and identifiers rather than a prose numeral. Four documents are admitted. FRM-GL-509 was already published, inside the FRM-GL-504 source file, and had never been tested against this clause; it is recorded rather than withdrawn, because a form that asks for a credential cannot itself require one. POL-EU-053 is admitted because POL-GL-053 states that it does not apply in the EEA, leaving no public notice discharging Articles 12 to 14 of Regulation (EU) 2016/679 for an EEA reader. POL-AU-053 is admitted because Australian Privacy Principle 1.4 requires the policy to be available free of charge and this document replaces Annexure B of POL-GL-053 in that market. STM-GL-037 is admitted because Regulation (EU) 2023/2854 Article 28(1) requires the disclosure to be on the provider's website and Article 28(2) requires every contract to list it. Where a source file carries contains_doc_ids, every identifier in it is tested against this clause separately, which is the control that failed for FRM-GL-509, and clause 1.5 now says so. The proposed fifth positive publication finding was considered and rejected: it misnames the restrained person, every non-disclosure agreement, data processing agreement and POL-GL-510 restrains speech so the test is unbounded, and it reaches none of the documents admitted here. Four findings remain. POL-GL-500 clause 1.1 is corrected to cite POL-GL-502 rather than its own Section 4, which reviews credentials and not documents. |
| 2.0.0 | 23 August 2026 | Founder | Inverts the publication default. T_PUBLIC ceases to be the default tier and becomes a closed list of seventeen documents, enumerated at POL-GL-501 clause 1.5 and amendable only by this clause. The classification test at POL-GL-501 Section 1 is rewritten from public unless a reason to gate is found to gated unless a reason to publish is found, with four positive publication findings: a legal requirement to publish, an audience that can never hold a credential, an instrument that binds an unsigned visitor or constitutes the gate itself, and the entry point a reviewer needs in order to know what to request. The old sensitivity tests are retained unchanged as clause 1.6, which now selects which gate rather than whether to gate, and its residual case is T_NDA rather than T_PUBLIC. Clause 1.7 records why T_NDA carries the estate. The openness commitment is restated as a latency commitment and not a publication commitment: the four-business-hour target, the published latency and the prohibition on sales qualification at Section 3 are unchanged and now carry it. Section 6 is inverted to match: publishing outside the closed list is the exception, raising a tier is not. The T_NDA row of the tier table at POL-GL-500 clause 1.2 is corrected from zero, instant to the four-business-hour target actually implemented, which was always the behaviour of the administrator grant. 306 documents moved from T_PUBLIC to T_NDA in the same pass, and 53 marketing: publication keys were retired from their frontmatter. |
| 1.0.0 | 31 July 2026 | Founder | First publication. Five-tier model with T_PUBLIC as the default and a written justification required to gate; five-credential cap enforced in the database; domain auto-approval to remove admin latency; four-business-hour decision target with automatic escalation; closed list of refusal grounds; classification test as positive findings; withdrawal keeps the identifier. |