Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
Eight published Pensieve policies promise that something will be "counted and published in the Transparency Report". This document is where that promise is kept.
POL-GL-068 | Version 1.0.0 | Effective 01 August 2026 | Last Modified On 01 August 2026
Eight published Pensieve policies promise that something will be "counted and published in the Transparency Report". This document is where that promise is kept.
It does two things. Part One is the policy: what is published, how often, how each number is counted, what is never published, and who signs it. Part Two is the report template itself, rendered each period with that period's figures.
The governing commitment:
Edsol Edtech Pvt. Ltd.publishes this report on schedule whether the numbers are good, bad, or zero, and states which.
The report covers Edsol Edtech Pvt. Ltd. as a whole, across all four deployment models. Where a figure
differs materially by deployment model (availability, sub-processor exposure, support), it is broken down
by model. DM-4 figures are marked, because Pensieve does not operate that infrastructure and cannot
report on what it cannot see.
1.1 Twice a year. Reporting periods are the two halves of Edsol Edtech Pvt. Ltd.'s financial year,
which runs 1 April to 31 March.
1.2 Published within sixty (60) days of the end of each period, at
https://trust.pensievelabs.org/transparency, at the Public tier, requiring no account and no e-mail address.
1.3 First edition. The first report is targeted at Roadmap transparency report target, owned by
Roadmap transparency report owner.
1.4 A period is never skipped. Where there is nothing to report in a category, the report says "Zero"
and not "not applicable". A report that omits a category because the number is uncomfortable is a breach of
this Policy and is treated as an internal incident under POL-GL-112.
1.5 Every edition is archived permanently, with its version and content hash, and remains retrievable after it is superseded. Superseding an edition does not remove it.
Each row names the operational register the figure is drawn from, so the number is auditable rather than asserted.
| # | Metric | Source of record | Committed by |
|---|---|---|---|
| M-1 | Government and law-enforcement demands received, by type and by country | Law-enforcement request log | POL-GL-067 |
| M-2 | Demands complied with in full, in part, and rejected | Law-enforcement request log | POL-GL-067 |
| M-3 | Demands where the affected customer was notified, and where notification was prohibited | Law-enforcement request log | POL-GL-067 |
| M-4 | Data Principal requests received, by right exercised, and the proportion answered within the statutory period | Grievance and rights register | POL-GL-066, POL-GL-053 |
| M-5 | Grievances received, upheld, and the median days to closure | Grievance register | POL-GL-066 |
| M-6 | Personal data breaches notified to a regulator, to customers, and to affected individuals | REG-GL-203 |
DIS-GL-016 |
| M-7 | Security incidents by severity, and the number affecting customer data | REG-GL-203 |
POL-GL-112 |
| M-8 | Vulnerability reports received, valid reports, median days to remediate by severity | REG-GL-204 |
POL-GL-059 |
| M-9 | Sub-processor additions, replacements and removals; emergency replacements; objections received and their outcomes | DIS-GL-010 |
POL-GL-055 |
| M-10 | Availability achieved, by deployment model, against target; Service Credits accrued | Service Reports | SLA-GL-001, DIS-GL-030 |
| M-11 | Accessibility barriers reported, assessed within target, and remediated | Accessibility report log | POL-GL-061 |
| M-12 | Artificial-intelligence capabilities in general availability and in pre-release; capabilities enabled to process production patient data | Model inventory, enablement records | POL-GL-060, POL-GL-058 |
| M-13 | Support: tickets by severity, first-response and restoration performance, escalations invoked | Support Center | POL-GL-056 |
| M-14 | Throttles applied under the fair-use policy, and overage charges raised (expected to be zero) | Rate-limit and billing records | POL-GL-057 |
| M-15 | Refunds and Service Credits issued, and offboardings where data return was completed on time | Credit note register, offboarding records | POL-GL-063, WPR-GL-400 |
| M-16 | Policy exceptions and waivers open at period end | REG-GL-210 |
POL-GL-000 |
| M-17 | Whistleblower and internal grievance reports received, and how many were investigated | Internal register | POL-IN-308 |
| M-18 | Certifications held | Not applicable | Always stated, and currently none |
2.1 M-18 is not a joke row. Pensieve holds no certifications, and the report says so in every edition rather than allowing an absence of mention to be read as an acquisition.
Numbers without definitions are decoration. These definitions do not change between editions without being flagged.
3.1 Counted when received, not when resolved. An item received in one period and closed in the next is counted in the period of receipt, and the closure is reflected in the later period's median.
3.2 One demand, one count. A single legal demand covering several individuals is one demand; the number of individuals is reported separately. A demand re-served after being rejected is a new demand.
3.3 Medians, not means. Central tendency is reported as a median, because a single prolonged case distorts a mean and flatters or damns Pensieve unfairly.
3.4 Small numbers. Where a count in a category is between one and four, the report states "fewer than 5" rather than the exact figure, because with a small number of customers an exact count can identify the hospital concerned. The threshold is reviewed as the customer base grows and any change is disclosed.
3.5 Zero is reported as zero. See 1.4.
3.6 No customer is named, and no figure is broken down in a way that would identify one, except with a
signed ADD-GL-020.
3.7 Restatements. Where a figure in a published edition is found to be wrong, it is corrected in the next edition and an erratum is added to the archived edition. Pensieve does not silently amend a published number.
3.8 Basis of preparation is stated in every edition: the period, the systems the figures were drawn from, the extraction date, and any known limitation.
4.1 Personal data of any kind, including patient data, and including in an example.
4.2 The name of a customer, without consent under ADD-GL-020.
4.3 Detail of an unremediated vulnerability, or anything else exploitable. Aggregate counts only, in
line with POL-GL-059.
4.4 The content of a specific legal demand, or anything Pensieve is lawfully prohibited from disclosing. Where a prohibition applies, the report states that a prohibited category exists and the fact of the prohibition, to the extent the law permits.
4.5 Anything covered by an ongoing regulatory or law-enforcement process where publication would prejudice it.
4.6 No warrant canary. Pensieve does not operate a warrant canary and does not intend to. A canary is a device for signalling by omission; its legal effectiveness is unsettled in Pensieve's home jurisdiction, and a device that may not work is worse than an honest statement that Pensieve reports what it is permitted to report and no more.
5.1 Approved and signed by the Director before publication. Approval is
recorded.
5.2 Prepared from the registers, not from recollection. Each figure carries the register it came from and the extraction date, so it can be recomputed.
5.3 Reviewed against this Policy before publication: every metric present, every definition unchanged or flagged, no prohibited content.
5.4 Failure to publish within the sixty-day window is logged in REG-GL-203 and the reason published
with the late edition.
5.5 Independent verification. No third party audits these figures today. Where an independent assessment is later obtained, its scope will be stated; until then every figure is self-reported, and the report says so on its face.
The following is rendered for each period. Fields are completed from the registers named in 2.
Period covered: to |
Extracted on: | Prepared under: POL-GL-068
v1.0.0 | Basis: self-reported, unaudited
| Metric | This period | Previous period |
|---|---|---|
| Demands received | |
|
| Of which, from a court or tribunal | |
|
| of which, from a police or investigative authority | |
|
| of which, from a regulator or statutory body | |
|
| Complied with in full | |
|
| Complied with in part | |
|
| Rejected, narrowed or challenged | |
|
| Customer notified before disclosure | |
|
| Notification prohibited by law | |
|
| Metric | This period | Previous period |
|---|---|---|
| Data Principal requests received | |
|
| Answered within the statutory period | |
|
| Grievances received / upheld | / |
|
| Median days to close a grievance | |
|
| Personal data breaches notified to a regulator | |
|
| Personal data breaches notified to customers | |
|
| Metric | This period | Previous period |
|---|---|---|
| Security incidents, Severity 1 / 2 / 3 | / / |
|
| Incidents affecting customer data | |
|
| Vulnerability reports received / valid | / |
|
| Median days to remediate, critical / high | / |
|
| Independent assessments completed in the period | |
|
| Metric | This period |
|---|---|
| Additions / replacements / removals | / / |
Emergency replacements, with reasons published in DIS-GL-010 |
|
| Objections received / sustained | / |
| Metric | DM-1 |
DM-2 |
DM-3 |
DM-4 |
|---|---|---|---|---|
| Availability achieved against target | |
|
|
Not measured by Pensieve |
| Service Credits accrued | |
|
|
|
| Severity 1 tickets / met first-response target | / |
|||
| Customer-initiated escalations to E-3 or above | |
| Metric | This period |
|---|---|
| Artificial-intelligence capabilities: general availability / pre-release | / |
| Capabilities permitted to process production patient data | |
| Accessibility barriers reported / assessed within target / remediated | / / |
| Fair-use throttles applied | |
| Overage charges raised | |
| Metric | This period |
|---|---|
| Refunds issued, by ground | |
| Offboardings completed | |
| Data returned within the committed window | |
| Deletion certificates issued | |
| Open policy exceptions at period end | |
| Statement | Position this period |
|---|---|
| Certifications held | None. Edsol Edtech Pvt. Ltd. holds no ISO, SOC 2, HITRUST or equivalent certification |
| Customer data used to train any model | No |
| Warrant canary operated | No; see POL-GL-068 4.6 |
| Figures independently audited | |
| Restatements of a previously published figure | |
Approved by [TO BE SUPPLIED], Director, on
.
| # | Testable statement | Evidence |
|---|---|---|
| T-1 | A report was published within 60 days of each period end | Publication timestamps against period ends |
| T-2 | Every metric in 2 appears in every edition, with zero stated where zero | Edition-by-edition completeness check |
| T-3 | Every figure can be recomputed from the named register at the stated extraction date | Recomputation of a sample of five metrics per edition |
| T-4 | No edition contains personal data or a customer name without consent | Pre-publication review record |
| T-5 | Every restatement carries an erratum on the archived edition | Archive review |
| T-6 | Every archived edition remains retrievable at its original address | Link check, semi-annually |
| T-7 | Each metric definition is unchanged from the previous edition, or the change is flagged | Definition diff per edition |
7.1 This Policy is reviewed semi-annually, with each edition, under POL-GL-502.
7.2 A metric is added when a new commitment to publish is made in any other policy. A metric is removed only where the underlying activity has ceased, and the removal is explained in the edition in which it disappears.
7.3 The counting rules in 3 are not changed to improve a number.
| Token | Meaning |
|---|---|
Roadmap transparency report owner |
Role accountable for preparing and publishing each edition |
| Document | Relationship |
|---|---|
POL-GL-067 Legal and Law Enforcement Request Policy |
Source of M-1 to M-3 |
POL-GL-066 Grievance Redressal Policy, POL-GL-053 Privacy Policy |
Source of M-4 and M-5 |
POL-GL-059 Vulnerability Disclosure Policy |
Source of M-8 |
POL-GL-055 Sub-Processor Notification and Objection Terms, DIS-GL-010 |
Source of M-9 |
SLA-GL-001, DIS-GL-030 |
Source of M-10 |
POL-GL-056, POL-GL-057, POL-GL-060, POL-GL-061, POL-GL-063 |
Sources of M-11 to M-15 |
REG-GL-203, REG-GL-204, REG-GL-210 |
The operational registers behind the figures |
POL-GL-502 Document Review and Staleness Policy |
Review cadence and staleness rules |
ADD-GL-020 Reference and Publicity Consent |
The only basis on which a customer could be named |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-01 | Founder / Pensieve Labs | First published version. Consolidates the eight separate "will be published in the Transparency Report" promises made across the policy set into eighteen defined metrics, each tied to a named register; fixes a semi-annual cadence with a sixty-day publication window and a no-skipped-category rule; publishes counting rules including a fewer-than-five suppression threshold and a no-silent-restatement rule; states that no warrant canary is operated and why; and provides the full report template. |
POL-GL-068 v1.0.0 | Last Modified On 01 August 2026 | Review due
31 January 2027 | Published at https://trust.pensievelabs.org