Search all 586 artefacts by title, document ID or content.
Policy | Family 15, Trust Center Meta
To state who may see what in the Pensieve Labs Trust Center, on what basis, for how long, and how access is granted, refused, reviewed and withdrawn.
This document is the source of truth for: trust-center-access-rules, credential-cap, domain-auto-approval-rules, document-tier-assignment-rules, publication-approval-workflow
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
POL-GL-500 | Version 2.2.0 | Last Modified On 29 August 2026
To state who may see what in the Pensieve Labs Trust Center, on what basis, for how long, and how
access is granted, refused, reviewed and withdrawn.
https://trust.pensievelabs.org and everything published on it. Binds Edsol Edtech Pvt. Ltd. and every
person who holds or requests a credential.
1.1 The public tier is a closed list, not a default. T_PUBLIC is never reached by the absence of a
reason to gate. A document is public only where the test at Section 1 of POL-GL-501 positively places it
there, and the resulting list is short, enumerated in full at POL-GL-501 clause 1.5, and reconciled
against the register at every review under POL-GL-502. Everything else opens on request.
A gate is still a choice with a cost, and it is not the safe option: Pensieve Labs pays that cost
down in latency rather than in publication. The clickwrap is one click, the decision target is four
business hours, the latency is printed on the lock itself, and no sales qualification is asked for at any
point (Section 3). An unknown vendor cannot afford to make a hospital's reviewer wait. It can afford to
make the wait short, and to say in advance exactly how short.
1.2 Five tiers, and no others.
| Tier | Who | Gate | Typical decision latency |
|---|---|---|---|
T_PUBLIC |
Anyone. Indexable by search engines | None | Zero |
T_EMAIL |
Anyone supplying a work e-mail | E-mail capture | Zero, instant |
T_NDA |
Anyone accepting the click-through mutual NDA (NDA-GL-002). The tier that carries most of the estate |
Clickwrap, recorded as an evidentiary event, then an administrator grant | Target ≤ 4 business hours |
T_CLIENT |
Named users of one client workspace | Admin-approved credential | Target ≤ 4 business hours |
T_INTERNAL |
Pensieve Labs administrators |
Passkey / WebAuthn | n/a |
1.3 A maximum of five active credentials per client hospital. Enforced in the database by a partial
unique index, not by process. A sixth request triggers NTC-GL-508 and FRM-GL-509.
1.4 Access is granted to a person, never to a role, a shared mailbox or a distribution list. Requests
from info@, admin@, it@ and equivalents are declined and redirected to a named individual, with the
reason given.
1.5 Domain-based auto-approval. The administrator may configure auto-approval for the verified e-mail domain of an existing Customer or of a hospital with an executed NDA. Auto-approval:
1.5.1 applies to T_NDA and T_CLIENT only, never to T_INTERNAL;
1.5.2 is recorded per domain with the person who authorised it and the date;
1.5.3 does not lift the five-credential cap;
1.5.4 is reviewed at each access review under Section 4;
1.5.5 is removed automatically when the Customer's Agreement ends.
Auto-approval exists to take the administrator off the critical path. A hospital's security reviewer
waiting overnight for a credential is a day of T2C spent on nothing.
1.6 Decision service level. Every access request receives a decision within one Business Day, and
Pensieve Labs targets four business hours. A request that has not been decided within one Business
Day is escalated to the Founder automatically.
1.7 Every request receives a reply. Approval (NTC-GL-505) or refusal (NTC-GL-506). Silence is not a
decision. A refused requester is a future buyer and the refusal says what is available without a
credential.
1.8 Grounds on which access is refused. Only these:
| Ground | Reasoning |
|---|---|
| Not a work e-mail, or the domain cannot be associated with an organisation | Attribution is the whole basis of the gate |
| A shared or role mailbox | Section 1.4 |
The requester is a competitor in the supply of hospital software, and the request is for T_CLIENT or for material at T_NDA that would disclose implementation detail |
Legitimate, and stated plainly rather than dressed as a technicality |
| The five-credential cap is reached for that hospital | NTC-GL-508 and FRM-GL-509 apply |
| A prior grant to the same person or organisation was revoked under Section 5 | |
| A sanctions or export-control restriction applies | STM-GL-032 |
Not a ground: being a small hospital, being a consultant acting for a hospital, being a journalist,
being a researcher, being a student, or being a person Pensieve Labs would rather not answer.
1.9 Duration.
| Grant | Expires |
|---|---|
T_EMAIL |
Does not expire; the e-mail is retained under POL-GL-053 |
T_NDA |
12 months from acceptance, renewable by re-accepting NDA-GL-002 |
T_CLIENT: active Customer |
With the Agreement, plus the Exit Period |
T_CLIENT: prospective Customer under evaluation |
90 days, extendable once by 90 days on request |
T_INTERNAL |
With employment or engagement; removed on the leaver step of POL-GL-321 within 4 hours |
1.10 Watermarking. Every document served at T_NDA and T_CLIENT carries a per-viewer watermark, baked
into the PDF at render time. POL-GL-510 is the notice given to viewers.
| Step | Action | Owner | Target |
|---|---|---|---|
| 1 | Requester submits FRM-GL-504 |
Requester | Not applicable |
| 2 | Auto-approval rules evaluated | System | Immediate |
| 3 | Where no rule matches, the request appears in the admin console with the domain, any existing relationship, and the documents requested | System | Immediate |
| 4 | Administrator approves or refuses, with a recorded reason | Founder / Trust Center admin | 4 business hours, escalated at 1 Business Day |
| 5 | NTC-GL-505 or NTC-GL-506 sent |
System | Immediate on decision |
| 6 | Credential provisioned; the grant, its tier, its expiry and its authoriser are written to the audit log | System | Immediate |
Pensieve Labs will not ask forRequired: name, work e-mail, organisation, role, and which documents or which subject they need.
Pensieve Labs does not require, as a condition of access: a phone number, a budget, a timeline, a
purchase intent, a signed paper NDA where the clickwrap suffices, or a sales conversation.
A trust center that extracts a sales qualification before showing a security document is a lead-capture
form wearing a trust center's clothes, and hospital security reviewers recognise it immediately.
| Review | Frequency | Owner | Evidence |
|---|---|---|---|
All active T_CLIENT credentials, per hospital |
Quarterly | Trust Center admin | Entry in the Access Review Register (REG-GL-208) with the date, the reviewer and the outcome per credential |
| All auto-approval domain rules | Quarterly | Trust Center admin | Same register |
All T_INTERNAL accounts |
Quarterly, and on every leaver | Founder | Same register |
| Expired-but-active grants | Weekly, automated | System | Exception report; any grant past expiry is revoked automatically |
5.1 Access is revoked when: the person leaves the hospital and the hospital tells Pensieve Labs or
the credential fails a quarterly review; the Agreement ends and the Exit Period expires; a grant expires;
the terms in POL-GL-052 or NDA-GL-002 are breached; a watermarked document is found outside its
permitted audience (POL-GL-510); or the hospital asks.
5.2 Revocation is notified by NTC-GL-507, stating the ground, the date and the route to reinstatement.
Revocation without notice is used only where notice would defeat its purpose, and notice follows within
2 Business Days.
5.3 Revocation does not delete the audit trail. Which documents that person accessed, and when, is
retained under POL-GL-503.
An exception to this Policy is granted only by the Founder, is recorded in the Exception & Waiver Register
(REG-GL-210) with a reason and an expiry date, and is reviewed at expiry. An exception that publishes a document
outside the closed list at POL-GL-501 clause 1.5 is the exception this Section exists to control, and
it is granted only as an amendment to that clause. Raising a tier above T_NDA on a positive finding
under clause 1.6 is not an exception and needs no waiver.
To decide, repeatably, what tier a document is published at, who approves publication, and what must be true before a document appears on the Trust Center at all.
A document is gated unless one of the following is positively true of it. Each is a positive finding, recorded against the document, and the finding is what places a document in the public tier. The absence of a reason to gate is not a finding and does not make a document public.
| Test | If true, tier |
|---|---|
| The law requires the document to be available to anyone: a privacy notice, a cookie and consent notice, a grievance officer notice, a data principal rights channel, a vulnerability disclosure address published under RFC 9116, an accessibility statement | T_PUBLIC |
| The document is addressed to a person who can never hold a credential: a patient, a member of hospital staff who is not a Customer contact, a job applicant, an unsolicited security researcher | T_PUBLIC |
| The document binds a visitor who has signed nothing, or is itself the instrument of the gate: the site and Trust Center terms, the click-through NDA, this policy, the access request form | T_PUBLIC |
The document is the entry point a reviewer needs before they can tell what to request: who Edsol Edtech Pvt. Ltd. is, what assurance does and does not exist, and the regulatory boundary of the product |
T_PUBLIC |
| None of the above | Gated. Clause 1.6 sets which gate |
1.1 The public tier is short by design, and the openness is delivered as latency. A hospital cannot
evaluate what it cannot read, and an unknown vendor cannot afford to be coy. Pensieve Labs answers
that with a gate that opens in hours and never asks a sales question, and not with an open estate that
serves contract templates, internal control policies and assurance evidence to anyone who arrives without
saying who they are. The security whitepaper, the architecture overview, the sub-processor register, the
DPA, the SLA, the standard MSA, the control policy set, the framework mappings and the assurance evidence
are T_NDA: one click, an administrator grant, a four business hour target, and the latency printed on
the lock. What used to be published is not withheld. It is dated, watermarked, and traceable to the
person who asked for it, which is what makes it safe to hand over the sensitive parts at all.
1.2 No certification claims. Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001, SOC 2, HITRUST, CE or ARTG
certification. No document may be published that states or implies otherwise. The Trust Center carries an
Assurance & Evidence section, not a Certifications section. Where a control set is mapped to a standard,
the correct form is: "controls are mapped to ISO/IEC 27001:2022 Annex A. Edsol Edtech Pvt. Ltd. is not
certified to ISO/IEC 27001. The Statement of Applicability is published at …"
1.3 Nothing is published that has not been reviewed for the presence of another customer's information.
A single hospital's name in a screenshot, log excerpt, sample report or example is a breach of
confidentiality and of MSA-IN-001 clause 12. Examples use obviously fictional names.
1.4 Redaction is a version, not an edit. Where a T_NDA document has a publishable summary, the summary
is a separate document with its own doc_id, its own tier and its own review date. A document is never
served in two different forms from one identifier.
1.5 The public list, in full. The table below is the list, and no others. It carries twenty-one rows
and twenty-two document identifiers, because POL-GL-500 and POL-GL-501 are one instrument published
under two identifiers. The register must therefore show exactly twenty-two T_PUBLIC records. The
Founder performs that reconciliation, at each review of this Policy under POL-GL-502 clause 1.2, which
is twelve months for a K_POLICY, and on any trigger at POL-GL-502 clause 1.7, and records the count
found in the change history below. Where a source file carries contains_doc_ids, every identifier in it
is tested against this clause separately: one frontmatter tier emitting two register records is the control
failure that published FRM-GL-509 unexamined. A document joins this list only by an amendment to this
clause, approved by the Founder under Section 2 and recorded. A document that no longer satisfies the
finding beside it leaves the list at the next review under POL-GL-502.
1.5.1 An application is not an admission. Several instruments across the estate record an amendment to this clause as a dependency of their own, in a dependency ledger or an equivalent table, and state that they are gated until it is made. Such a row is an application, not an amendment. It does not place the document on the list, it does not change the document's register record, and it is never read as making the document public. The list is only what the table below carries, and the only evidence that a document has joined it is a row in that table together with a change-history row recording the Founder's approval under Section 2. An author who finds a ledger row asserting that a document has been admitted must check the table; where the table does not carry the document, the document is not public and the ledger row is the thing that is wrong.
| Document | The finding that makes it public |
|---|---|
POL-GL-053 Privacy Policy |
Required by law to be available to anyone |
POL-GL-054 Cookie Policy and Consent Notice |
Required by law; the consent banner links to it |
NTC-GL-023 Notice to the Data Principal at the Point of Collection |
Must be readable at the moment of collection |
FRM-GL-505 Data Principal Rights Request Form |
A rights channel cannot itself be gated |
POL-GL-066 Grievance Redressal Policy and Grievance Officer Notice |
The grievance officer must be findable without a credential |
POL-GL-059 Vulnerability Disclosure Policy and security.txt |
RFC 9116 requires a public well-known address |
POL-GL-061 Accessibility Statement |
Required by law to be available to anyone |
POL-IN-320 Candidate and Recruitment Privacy Notice |
An applicant holds no credential, and a recruitment-fraud warning behind a gate warns nobody |
DIS-GL-037 Notice for Patients and Hospital Staff |
A patient can never sign an NDA |
POL-GL-051 Website Terms of Use |
Binds a visitor who has signed nothing |
POL-GL-052 Trust Center Terms of Use |
Binds a visitor who has signed nothing |
NDA-GL-002 Click-through Mutual Non-Disclosure Agreement |
Must be readable before it is accepted |
POL-GL-500 This policy, with POL-GL-501 |
A gate that will not explain itself is a dead end |
FRM-GL-504 Trust Center Request Access Form |
The entry point to everything else |
STM-GL-028 Company Profile and Corporate Overview |
Who the counterparty is |
WPR-GL-005 Trust and Assurance Overview |
What exists, what is coming, and what does not exist |
DIS-GL-028 Clinical Safety Boundary Statement |
A market-facing regulatory claim; gating it would read as evasion |
FRM-GL-509 Additional Credential Request |
A form that asks for a credential cannot itself require one. Published since first release inside the FRM-GL-504 source file, and recorded here rather than left off the list |
POL-EU-053 Privacy Policy, GDPR Variant |
Required by law to be available to anyone. POL-GL-053 states that it does not apply to a person in the EEA, so this is the only notice discharging Articles 12 to 14 of Regulation (EU) 2016/679 for an EEA reader |
POL-AU-053 Privacy Policy, Australia |
Required by law to be available to anyone. Australian Privacy Principle 1.4 requires the APP 1.3 policy to be available free of charge, and this document replaces Annexure B of POL-GL-053 for anyone in Australia |
STM-GL-037 Government Access and Lawful Requests Statement |
Required by law to be available to anyone. Regulation (EU) 2023/2854 Article 28(1) requires a provider of data processing services to make the jurisdiction of its ICT infrastructure and its anti-access measures available on its website, and Article 28(2) requires every contract to list that website |
1.6 Which gate a document sits behind. Applied only after the test at the head of this Section has returned gated. Each row is a positive finding, recorded against the document.
| Test | If true, tier |
|---|---|
| The document identifies a specific hospital, its commercials, its configuration or its people | T_CLIENT |
| The document is an internal operating instruction with no external audience and no evidential value | T_INTERNAL |
The document contains findings from an unremediated security test, internal hostnames, IP ranges, network topology at the level of DIS-GL-007, or anything that materially assists an attacker |
T_NDA |
| The document contains business-continuity test evidence, insurance policy wordings, or the full text of a third-party contract | T_NDA |
| The document's value is primarily as a lead magnet and its content is genuinely non-sensitive | T_EMAIL: used sparingly; the friction is real |
| None of the above | T_NDA |
1.7 T_NDA is the resting place of the estate, and that is deliberate. The clickwrap is the cheapest
gate that produces a named, dated, enforceable record of who holds the document. It is what lets
Pensieve Labs publish the sensitive material at all rather than write a thinner version of it. Where
a reviewer needs a document faster than the four business hour target, POL-GL-500 clause 1.5 domain
auto-approval exists precisely to take the administrator off the path.
| Step | Action | Owner |
|---|---|---|
| 1 | Draft authored against SPEC-005, with complete frontmatter | Author |
| 2 | Classification test at Section 1 applied; tier and the positive finding recorded | Author |
| 3 | Technical review: factual accuracy, per deployment model | Owning role |
| 4 | Legal review, only for statements creating liability, a certification implication, a medical claim, or a confidentiality breach | Legal |
| 5 | Publication approval | Founder for T_PUBLIC; owning role for all other tiers |
| 6 | review_due_on set; document registered; NTC-GL-020 entry queued |
System |
2.1 Legal does not decide whether to publish a security bulletin. NTC-GL-021 Section 11 governs.
2.2 Every published document carries, on every page: doc_id, version, Last Modified On, tier,
and, for the legal letterhead variant, the SHA-256 short hash and the verification QR resolving to
https://trust.pensievelabs.org/verify/. SPEC-003 Section D.2.
2.3 A document is never silently changed. A change of substance is a new version with a change-history row. A typographical correction is a patch version and is still recorded.
2.4 Withdrawal. A withdrawn document keeps its doc_id, is marked Withdrawn with the date and the
reason, and remains retrievable. Its successor is named. Trust centers that quietly delete documents are
the reason buyers take their own copies.
All security, legal, privacy and compliance copy on https://pensievelabs.org is served from the Trust
Center. The marketing site holds no separate copy and no separate version. Each document declares the
marketing paths it feeds in source_of_truth_for. A marketing page that restates a Trust Center fact in
its own words is a defect and is raised as one.
| Role | Accountable for |
|---|---|
| Author | Frontmatter, classification test, accuracy, no literals, deployment-model correctness |
| Owning role | Technical accuracy and the review date |
| Legal | Liability, certification implications, medical claims, confidentiality |
| Founder | T_PUBLIC publication approval, and every exception |
A document published at the wrong tier is re-tiered within 1 Business Day of discovery, the exposure is
assessed, and the event is recorded in the Incident Register (REG-GL-203) where anything at T_CLIENT or
above was exposed. Where another hospital's information was exposed, NTC-GL-002 applies.
| Topic | Document |
|---|---|
| Trust Center terms of use | POL-GL-052 |
| Click-through mutual NDA | NDA-GL-002 |
| Data classification (of customer data, not documents) | DIS-GL-022 |
| Document review and staleness | POL-GL-502 |
| Audit log retention | POL-GL-503 |
| Watermarking and leak tracing | POL-GL-510 |
| Access request and additional credential forms | FRM-GL-504, FRM-GL-509 |
| Access, refusal, revocation and cap e-mails | NTC-GL-505 to NTC-GL-508 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 2.2.0 | 29 August 2026 | Founder | Conforming pass on the closed list. No document's tier changes and no document joins or leaves the list. Every one of the twenty-one rows at clause 1.5, carrying twenty-two identifiers, was checked against the register on 29 August 2026. The register shows exactly twenty-two T_PUBLIC records and they are the same twenty-two identifiers, so the reconciliation clause 1.5 requires returns clean and no row is corrected. No amendment to this clause recorded elsewhere in the estate as landed was found missing from the table. Clause 1.5 previously required that reconciliation without naming who performs it or when; it now names the Founder, the twelve-month K_POLICY cadence at POL-GL-502 clause 1.2 and the event triggers at POL-GL-502 clause 1.7, and requires the count found to be recorded in this table. New clause 1.5.1 states that a row in another instrument's dependency ledger applying for admission to this clause is an application and not an amendment: it does not place the document on the list, does not change its register record, and is never read as making it public. Four such rows stand today and each is correct to describe its document as gated: POL-GL-074 clause 15.1 row D-8 and REG-GL-218 clause 7.4 row D-8, both for POL-GL-074; REP-GL-033 row A-1 for itself and row A-6 for POL-GL-074; and DIS-GL-823 clause 10.1.3 for REP-GL-033. Neither POL-GL-074 nor REP-GL-033 is admitted here. Admission is the Founder's decision under Section 2 on the positive findings at Section 1, it carries a register re-tier with it, and a conforming pass does not make it. |
| 2.1.0 | 29 August 2026 | Founder | Amends clause 1.5, the first amendment to the closed list. The list is restated as twenty-one rows and twenty-two document identifiers, counted separately because POL-GL-500 and POL-GL-501 are one instrument under two identifiers, and reconciled against the register at every review under POL-GL-502. Version 2.0.0 said seventeen documents while its table carried seventeen rows enumerating eighteen identifiers and the register carried nineteen T_PUBLIC records; the drift is corrected by counting rows and identifiers rather than a prose numeral. Four documents are admitted. FRM-GL-509 was already published, inside the FRM-GL-504 source file, and had never been tested against this clause; it is recorded rather than withdrawn, because a form that asks for a credential cannot itself require one. POL-EU-053 is admitted because POL-GL-053 states that it does not apply in the EEA, leaving no public notice discharging Articles 12 to 14 of Regulation (EU) 2016/679 for an EEA reader. POL-AU-053 is admitted because Australian Privacy Principle 1.4 requires the policy to be available free of charge and this document replaces Annexure B of POL-GL-053 in that market. STM-GL-037 is admitted because Regulation (EU) 2023/2854 Article 28(1) requires the disclosure to be on the provider's website and Article 28(2) requires every contract to list it. Where a source file carries contains_doc_ids, every identifier in it is tested against this clause separately, which is the control that failed for FRM-GL-509, and clause 1.5 now says so. The proposed fifth positive publication finding was considered and rejected: it misnames the restrained person, every non-disclosure agreement, data processing agreement and POL-GL-510 restrains speech so the test is unbounded, and it reaches none of the documents admitted here. Four findings remain. POL-GL-500 clause 1.1 is corrected to cite POL-GL-502 rather than its own Section 4, which reviews credentials and not documents. |
| 2.0.0 | 23 August 2026 | Founder | Inverts the publication default. T_PUBLIC ceases to be the default tier and becomes a closed list of seventeen documents, enumerated at POL-GL-501 clause 1.5 and amendable only by this clause. The classification test at POL-GL-501 Section 1 is rewritten from public unless a reason to gate is found to gated unless a reason to publish is found, with four positive publication findings: a legal requirement to publish, an audience that can never hold a credential, an instrument that binds an unsigned visitor or constitutes the gate itself, and the entry point a reviewer needs in order to know what to request. The old sensitivity tests are retained unchanged as clause 1.6, which now selects which gate rather than whether to gate, and its residual case is T_NDA rather than T_PUBLIC. Clause 1.7 records why T_NDA carries the estate. The openness commitment is restated as a latency commitment and not a publication commitment: the four-business-hour target, the published latency and the prohibition on sales qualification at Section 3 are unchanged and now carry it. Section 6 is inverted to match: publishing outside the closed list is the exception, raising a tier is not. The T_NDA row of the tier table at POL-GL-500 clause 1.2 is corrected from zero, instant to the four-business-hour target actually implemented, which was always the behaviour of the administrator grant. 306 documents moved from T_PUBLIC to T_NDA in the same pass, and 53 marketing: publication keys were retired from their frontmatter. |
| 1.0.0 | 31 July 2026 | Founder | First publication. Five-tier model with T_PUBLIC as the default and a written justification required to gate; five-credential cap enforced in the database; domain auto-approval to remove admin latency; four-business-hour decision target with automatic escalation; closed list of refusal grounds; classification test as positive findings; withdrawal keeps the identifier. |