Search all 478 artefacts by title, document ID or content.
Policy | Family 15, Trust Center Meta
To state who may see what in the Pensieve Labs Trust Center, on what basis, for how long, and how access is granted, refused, reviewed and withdrawn.
POL-GL-500 | Version 1.0.0 | Last Modified On 31 July 2026
To state who may see what in the Pensieve Labs Trust Center, on what basis, for how long, and how
access is granted, refused, reviewed and withdrawn.
https://trust.pensievelabs.org and everything published on it. Binds Edsol Edtech Pvt. Ltd. and every
person who holds or requests a credential.
1.1 The default tier is T_PUBLIC. A higher tier must be justified in writing against Section 2 of
POL-GL-501 and recorded. A gate is not the safe choice; it is a choice with a cost.
Pensieve Labs is an unknown vendor and every gate removes a day from a hospital's evaluation and adds
one to T2C.
1.2 Five tiers, and no others.
| Tier | Who | Gate | Typical decision latency |
|---|---|---|---|
T_PUBLIC |
Anyone. Indexable by search engines | None | Zero |
T_EMAIL |
Anyone supplying a work e-mail | E-mail capture | Zero, instant |
T_NDA |
Anyone who has accepted the mutual NDA (NDA-GL-002) and whose access request is approved |
NDA acceptance recorded as an evidentiary event, then an admin-approved credential | Target ≤ 4 business hours |
T_CLIENT |
Named users of one client workspace | Admin-approved credential | Target ≤ 4 business hours |
T_INTERNAL |
Pensieve Labs administrators |
Passkey / WebAuthn | n/a |
1.3 A maximum of five active credentials per client hospital. Enforced in the database by a partial
unique index, not by process. A sixth request triggers NTC-GL-508 and FRM-GL-509.
1.4 Access is granted to a person, never to a role, a shared mailbox or a distribution list. Requests
from info@, admin@, it@ and equivalents are declined and redirected to a named individual, with the
reason given.
1.5 Domain-based auto-approval. The administrator may configure auto-approval for the verified e-mail domain of an existing Customer or of a hospital with an executed NDA. Auto-approval:
1.5.1 applies to T_NDA and T_CLIENT only, never to T_INTERNAL;
1.5.2 is recorded per domain with the person who authorised it and the date;
1.5.3 does not lift the five-credential cap;
1.5.4 is reviewed at each access review under Section 4;
1.5.5 is removed automatically when the Customer's Agreement ends.
Auto-approval exists to take the administrator off the critical path. A hospital's security reviewer
waiting overnight for a credential is a day of T2C spent on nothing.
1.6 Decision service level. Every access request receives a decision within one Business Day, and
Pensieve Labs targets four business hours. A request that has not been decided within one Business
Day is escalated to the Founder automatically.
1.7 Every request receives a reply. Approval (NTC-GL-505) or refusal (NTC-GL-506). Silence is not a
decision. A refused requester is a future buyer and the refusal says what is available without a
credential.
1.8 Grounds on which access is refused. Only these:
| Ground | Reasoning |
|---|---|
| Not a work e-mail, or the domain cannot be associated with an organisation | Attribution is the whole basis of the gate |
| A shared or role mailbox | Section 1.4 |
The requester is a competitor in the supply of hospital software, and the request is for T_CLIENT or for material at T_NDA that would disclose implementation detail |
Legitimate, and stated plainly rather than dressed as a technicality |
| The five-credential cap is reached for that hospital | NTC-GL-508 and FRM-GL-509 apply |
| A prior grant to the same person or organisation was revoked under Section 5 | |
| A sanctions or export-control restriction applies | STM-GL-032 |
Not a ground: being a small hospital, being a consultant acting for a hospital, being a journalist,
being a researcher, being a student, or being a person Pensieve Labs would rather not answer.
1.9 Duration.
| Grant | Expires |
|---|---|
T_EMAIL |
Does not expire; the e-mail is retained under POL-GL-053 |
T_NDA |
12 months from the grant, renewable on a fresh access request while the NDA-GL-002 acceptance remains current |
T_CLIENT: active Customer |
With the Agreement, plus the Exit Period |
T_CLIENT: prospective Customer under evaluation |
90 days, extendable once by 90 days on request |
T_INTERNAL |
With employment or engagement; removed on the leaver step of POL-GL-321 within 4 hours |
1.10 Watermarking. Every document served at T_NDA and T_CLIENT carries a per-viewer watermark, baked
into the PDF at render time. POL-GL-510 is the notice given to viewers.
| Step | Action | Owner | Target |
|---|---|---|---|
| 1 | Requester submits FRM-GL-504 |
Requester | Not applicable |
| 2 | Auto-approval rules evaluated | System | Immediate |
| 3 | Where no rule matches, the request appears in the admin console with the domain, any existing relationship, and the documents requested | System | Immediate |
| 4 | Administrator approves or refuses, with a recorded reason | Founder / Trust Center admin | 4 business hours, escalated at 1 Business Day |
| 5 | NTC-GL-505 or NTC-GL-506 sent |
System | Immediate on decision |
| 6 | Credential provisioned; the grant, its tier, its expiry and its authoriser are written to the audit log | System | Immediate |
Pensieve Labs will not ask forRequired: name, work e-mail, organisation, role, and which documents or which subject they need.
Pensieve Labs does not require, as a condition of access: a phone number, a budget, a timeline, a
purchase intent, a signed paper NDA where the clickwrap suffices, or a sales conversation.
A trust center that extracts a sales qualification before showing a security document is a lead-capture
form wearing a trust center's clothes, and hospital security reviewers recognise it immediately.
| Review | Frequency | Owner | Evidence |
|---|---|---|---|
All active T_CLIENT credentials, per hospital |
Quarterly | Trust Center admin | Entry in the Access Review Register (REG-GL-208) with the date, the reviewer and the outcome per credential |
| All auto-approval domain rules | Quarterly | Trust Center admin | Same register |
All T_INTERNAL accounts |
Quarterly, and on every leaver | Founder | Same register |
| Expired-but-active grants | Weekly, automated | System | Exception report; any grant past expiry is revoked automatically |
5.1 Access is revoked when: the person leaves the hospital and the hospital tells Pensieve Labs or
the credential fails a quarterly review; the Agreement ends and the Exit Period expires; a grant expires;
the terms in POL-GL-052 or NDA-GL-002 are breached; a watermarked document is found outside its
permitted audience (POL-GL-510); or the hospital asks.
5.2 Revocation is notified by NTC-GL-507, stating the ground, the date and the route to reinstatement.
Revocation without notice is used only where notice would defeat its purpose, and notice follows within
2 Business Days.
5.3 Revocation does not delete the audit trail. Which documents that person accessed, and when, is
retained under POL-GL-503.
An exception to this Policy is granted only by the Founder, is recorded in the Exception & Waiver Register
(REG-GL-210) with a reason and an expiry date, and is reviewed at expiry. An exception that lowers a
tier is not an exception: it is the default under Section 1.1 and needs no waiver.
To decide, repeatably, what tier a document is published at, who approves publication, and what must be true before a document appears on the Trust Center at all.
A document is T_PUBLIC unless one of the following is true. Each is a positive finding, recorded
against the document.
| Test | If true, tier |
|---|---|
| The document identifies a specific hospital, its commercials, its configuration or its people | T_CLIENT |
The document contains findings from an unremediated security test, internal hostnames, IP ranges, network topology at the level of DIS-GL-007, or anything that materially assists an attacker |
T_NDA |
| The document contains business-continuity test evidence, insurance policy wordings, or the full text of a third-party contract | T_NDA |
The document sets out Pensieve Labs's security controls at procedure level, its personnel or labour practices, an assurance mapping or control-gap inventory, a notice or contract template, or comparable operating detail written for a counterparty under NDA rather than for the open web. The public tier keeps the summary form of the same subject: the whitepaper, the architecture overview and the standing disclosures |
T_NDA |
| The document is an internal operating instruction with no external audience and no evidential value | T_INTERNAL |
| The document's value is primarily as a lead magnet and its content is genuinely non-sensitive | T_EMAIL: used sparingly; the friction is real |
| None of the above | T_PUBLIC |
1.1 Publish more openly than the reference benchmark. Pensieve Labs publishes at T_PUBLIC, as a
deliberate decision: the security whitepaper, the architecture overview, the sub-processor register, the
DPA template, the SLA template, the standard MSA, the privacy policy, the deployment-model comparison, the
vulnerability disclosure policy, the exit and portability commitment, and the security bulletins. The
control-level policies, the assurance mappings and the detailed disclosures behind these summaries sit at
T_NDA. A hospital cannot evaluate what it cannot read, and an unknown
vendor cannot afford to be coy.
1.2 No certification claims. Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001, SOC 2, HITRUST, CE or ARTG
certification. No document may be published that states or implies otherwise. The Trust Center carries an
Assurance & Evidence section, not a Certifications section. Where a control set is mapped to a standard,
the correct form is: "controls are mapped to ISO/IEC 27001:2022 Annex A. Edsol Edtech Pvt. Ltd. is not
certified to ISO/IEC 27001. The Statement of Applicability is published at …"
1.3 Nothing is published that has not been reviewed for the presence of another customer's information.
A single hospital's name in a screenshot, log excerpt, sample report or example is a breach of
confidentiality and of MSA-IN-001 clause 12. Examples use obviously fictional names.
1.4 Redaction is a version, not an edit. Where a T_NDA document has a publishable summary, the summary
is a separate document with its own doc_id, its own tier and its own review date. A document is never
served in two different forms from one identifier.
| Step | Action | Owner |
|---|---|---|
| 1 | Draft authored against SPEC-005, with complete frontmatter | Author |
| 2 | Classification test at Section 1 applied; tier and the positive finding recorded | Author |
| 3 | Technical review: factual accuracy, per deployment model | Owning role |
| 4 | Legal review, only for statements creating liability, a certification implication, a medical claim, or a confidentiality breach | Legal |
| 5 | Publication approval | Founder for T_PUBLIC; owning role for all other tiers |
| 6 | review_due_on set; document registered; NTC-GL-020 entry queued |
System |
2.1 Legal does not decide whether to publish a security bulletin. NTC-GL-021 Section 11 governs.
2.2 Every published document carries, on every page: doc_id, version, Last Modified On, tier,
and, for the legal letterhead variant, the SHA-256 short hash and the verification QR resolving to
https://trust.pensievelabs.org/verify/. SPEC-003 Section D.2.
2.3 A document is never silently changed. A change of substance is a new version with a change-history row. A typographical correction is a patch version and is still recorded.
2.4 Withdrawal. A withdrawn document keeps its doc_id, is marked Withdrawn with the date and the
reason, and remains retrievable. Its successor is named. Trust centers that quietly delete documents are
the reason buyers take their own copies.
All security, legal, privacy and compliance copy on https://pensievelabs.org is served from the Trust
Center. The marketing site holds no separate copy and no separate version. Each document declares the
marketing paths it feeds in source_of_truth_for. A marketing page that restates a Trust Center fact in
its own words is a defect and is raised as one.
| Role | Accountable for |
|---|---|
| Author | Frontmatter, classification test, accuracy, no literals, deployment-model correctness |
| Owning role | Technical accuracy and the review date |
| Legal | Liability, certification implications, medical claims, confidentiality |
| Founder | T_PUBLIC publication approval, and every exception |
A document published at the wrong tier is re-tiered within 1 Business Day of discovery, the exposure is
assessed, and the event is recorded in the Incident Register (REG-GL-203) where anything at T_CLIENT or
above was exposed. Where another hospital's information was exposed, NTC-GL-002 applies.
| Topic | Document |
|---|---|
| Trust Center terms of use | POL-GL-052 |
| Click-through mutual NDA | NDA-GL-002 |
| Data classification (of customer data, not documents) | DIS-GL-022 |
| Document review and staleness | POL-GL-502 |
| Audit log retention | POL-GL-503 |
| Watermarking and leak tracing | POL-GL-510 |
| Access request and additional credential forms | FRM-GL-504, FRM-GL-509 |
| Access, refusal, revocation and cap e-mails | NTC-GL-505 to NTC-GL-508 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Founder | First publication. Five-tier model with T_PUBLIC as the default and a written justification required to gate; five-credential cap enforced in the database; domain auto-approval to remove admin latency; four-business-hour decision target with automatic escalation; closed list of refusal grounds; classification test as positive findings; withdrawal keeps the identifier. |