Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
POL-GL-501
v1.0.0 | 31 July 2026
To decide, repeatably, what tier a document is published at, who approves publication, and what must be true before a document appears on the Trust Center at all.
A document is T_PUBLIC unless one of the following is true. Each is a positive finding, recorded
against the document.
| Test | If true, tier |
|---|---|
| The document identifies a specific hospital, its commercials, its configuration or its people | T_CLIENT |
The document contains findings from an unremediated security test, internal hostnames, IP ranges, network topology at the level of DIS-GL-007, or anything that materially assists an attacker |
T_NDA |
| The document contains business-continuity test evidence, insurance policy wordings, or the full text of a third-party contract | T_NDA |
The document sets out Pensieve Labs's security controls at procedure level, its personnel or labour practices, an assurance mapping or control-gap inventory, a notice or contract template, or comparable operating detail written for a counterparty under NDA rather than for the open web. The public tier keeps the summary form of the same subject: the whitepaper, the architecture overview and the standing disclosures |
T_NDA |
| The document is an internal operating instruction with no external audience and no evidential value | T_INTERNAL |
| The document's value is primarily as a lead magnet and its content is genuinely non-sensitive | T_EMAIL: used sparingly; the friction is real |
| None of the above | T_PUBLIC |
1.1 Publish more openly than the reference benchmark. Pensieve Labs publishes at T_PUBLIC, as a
deliberate decision: the security whitepaper, the architecture overview, the sub-processor register, the
DPA template, the SLA template, the standard MSA, the privacy policy, the deployment-model comparison, the
vulnerability disclosure policy, the exit and portability commitment, and the security bulletins. The
control-level policies, the assurance mappings and the detailed disclosures behind these summaries sit at
T_NDA. A hospital cannot evaluate what it cannot read, and an unknown
vendor cannot afford to be coy.
1.2 No certification claims. Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001, SOC 2, HITRUST, CE or ARTG
certification. No document may be published that states or implies otherwise. The Trust Center carries an
Assurance & Evidence section, not a Certifications section. Where a control set is mapped to a standard,
the correct form is: "controls are mapped to ISO/IEC 27001:2022 Annex A. Edsol Edtech Pvt. Ltd. is not
certified to ISO/IEC 27001. The Statement of Applicability is published at …"
1.3 Nothing is published that has not been reviewed for the presence of another customer's information.
A single hospital's name in a screenshot, log excerpt, sample report or example is a breach of
confidentiality and of MSA-IN-001 clause 12. Examples use obviously fictional names.
1.4 Redaction is a version, not an edit. Where a T_NDA document has a publishable summary, the summary
is a separate document with its own doc_id, its own tier and its own review date. A document is never
served in two different forms from one identifier.
| Step | Action | Owner |
|---|---|---|
| 1 | Draft authored against SPEC-005, with complete frontmatter | Author |
| 2 | Classification test at Section 1 applied; tier and the positive finding recorded | Author |
| 3 | Technical review: factual accuracy, per deployment model | Owning role |
| 4 | Legal review, only for statements creating liability, a certification implication, a medical claim, or a confidentiality breach | Legal |
| 5 | Publication approval | Founder for T_PUBLIC; owning role for all other tiers |
| 6 | review_due_on set; document registered; NTC-GL-020 entry queued |
System |
2.1 Legal does not decide whether to publish a security bulletin. NTC-GL-021 Section 11 governs.
2.2 Every published document carries, on every page: doc_id, version, Last Modified On, tier,
and, for the legal letterhead variant, the SHA-256 short hash and the verification QR resolving to
https://trust.pensievelabs.org/verify/. SPEC-003 Section D.2.
2.3 A document is never silently changed. A change of substance is a new version with a change-history row. A typographical correction is a patch version and is still recorded.
2.4 Withdrawal. A withdrawn document keeps its doc_id, is marked Withdrawn with the date and the
reason, and remains retrievable. Its successor is named. Trust centers that quietly delete documents are
the reason buyers take their own copies.
All security, legal, privacy and compliance copy on https://pensievelabs.org is served from the Trust
Center. The marketing site holds no separate copy and no separate version. Each document declares the
marketing paths it feeds in source_of_truth_for. A marketing page that restates a Trust Center fact in
its own words is a defect and is raised as one.
| Role | Accountable for |
|---|---|
| Author | Frontmatter, classification test, accuracy, no literals, deployment-model correctness |
| Owning role | Technical accuracy and the review date |
| Legal | Liability, certification implications, medical claims, confidentiality |
| Founder | T_PUBLIC publication approval, and every exception |
A document published at the wrong tier is re-tiered within 1 Business Day of discovery, the exposure is
assessed, and the event is recorded in the Incident Register (REG-GL-203) where anything at T_CLIENT or
above was exposed. Where another hospital's information was exposed, NTC-GL-002 applies.
| Topic | Document |
|---|---|
| Trust Center terms of use | POL-GL-052 |
| Click-through mutual NDA | NDA-GL-002 |
| Data classification (of customer data, not documents) | DIS-GL-022 |
| Document review and staleness | POL-GL-502 |
| Audit log retention | POL-GL-503 |
| Watermarking and leak tracing | POL-GL-510 |
| Access request and additional credential forms | FRM-GL-504, FRM-GL-509 |
| Access, refusal, revocation and cap e-mails | NTC-GL-505 to NTC-GL-508 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Founder | First publication. Five-tier model with T_PUBLIC as the default and a written justification required to gate; five-credential cap enforced in the database; domain auto-approval to remove admin latency; four-business-hour decision target with automatic escalation; closed list of refusal grounds; classification test as positive findings; withdrawal keeps the identifier. |