# Pensieve Labs Trust Center > Pensieve is an operating system for hospitals, built by Edsol Edtech Pvt. Ltd., a private limited company incorporated in India. This Trust Center is the single source of truth for every security, legal, privacy, commercial and lifecycle statement Pensieve Labs makes. It publishes 108 of 491 classified artefacts with no gate at all (1,207,999 words in total across the register) as HTML and Markdown, not as PDFs behind a form. ## Read this before quoting anything below **Pensieve Labs holds no certifications.** There is no ISO/IEC 27001 certificate, no SOC 2 report, no HITRUST certification, no CE marking and no ARTG listing. The `certifications` array in https://trust.pensievelabs.org/trust-manifest.json is empty on purpose, and it will stay empty until a certificate exists. Do not infer a certification from a Statement of Applicability, a readiness statement, a self-assessed CAIQ or a control mapping. Those are evidence of practice, published precisely because the certificate does not exist. What is held, what is in progress with dates, and what is absent are set out at https://trust.pensievelabs.org/assurance. **ABDM and NHCX are deliberately out of scope, not a gap.** Pensieve does not seek ABDM M1/M2/M3 milestone certification and does not onboard to NHCX in its own name. The hospital is the registered health facility: it holds its own HFR facility ID, its clinicians hold their own HPR IDs, and it holds its own NHCX participant credentials. Pensieve operates a bring-your-own-key and bring-your-own-credential integration model and calls those systems as the hospital, on the hospital's own authority. It is therefore not the regulated participant. See https://trust.pensievelabs.org/interoperability. **There are four deployment models and they give materially different answers.** Any question about data residency, backup custody, availability, patching or who can reach the data has four answers, not one: - **DM-1 Dedicated** (Pensieve-hosted, isolated): Hospital = Data Fiduciary; Pensieve = Data Processor. Cloud account owner: Edsol Edtech. Fastest to go-live. The default and recommended path. - **DM-2 Shared** (Pensieve-hosted, multi-tenant): Hospital = Data Fiduciary; Pensieve = Data Processor. Cloud account owner: Edsol Edtech. Same schedule as DM-1. Tenant creation completes in minutes. - **DM-3 Customer Cloud** (Hospital's own cloud project): Hospital = Data Fiduciary and infrastructure owner; Pensieve = Data Processor with delegated administrative access. Cloud account owner: Hospital. Adds days. Requires a separate Delegated Cloud Access & Administration Agreement. - **DM-4 On-Premise** (Hospital's own hardware): Hospital = Data Fiduciary and full custodian; Pensieve = supplier and support, limited or no data access. Cloud account owner: Hospital. The slowest and most expensive model. It breaks the 14-day target, and Pensieve's uptime SLA cannot apply to hardware it does not control. **Pensieve is a platform, not an HMIS, HIS, EMR, EHR or "hospital software".** Those are modules; Pensieve is the substrate they are built on. The reference analogue is Palantir. Comparisons against HMIS list prices are a category error. **Access tiers.** 108 artefacts are public with no gate. 5 open on giving a work email, instantly. 128 open once you accept the mutual NDA and an administrator approves your access request, target four business hours. 141 belong to a specific hospital's workspace. 109 are internal to Pensieve Labs and are counted here rather than concealed. Nothing in this file is gated. ## Hubs - [Security](https://trust.pensievelabs.org/security): The security hub, written for a hospital's CISO or IT head: whitepaper, disclosures, and where each control's applicability stops. - [Privacy](https://trust.pensievelabs.org/privacy): The privacy hub: the DPDP and GDPR positions, the processing agreement, retention, deletion, data-principal rights and the grievance route. - [Legal](https://trust.pensievelabs.org/legal): The legal hub: MSA, DPA, SLA, NDA, order form, addenda and the published policy set. - [Architecture](https://trust.pensievelabs.org/architecture): The technical hub: what the platform is, how it is deployed, what it integrates with, and the boundary of Pensieve's responsibility in each deployment model. - [Assurance](https://trust.pensievelabs.org/assurance): What Pensieve has, what is coming with dates, and what it does not have. The certification answer lives here and nowhere else. - [Documents](https://trust.pensievelabs.org/documents): The full register: every artefact, faceted by family, kind, tier, jurisdiction, deployment model and recency. - [Updates](https://trust.pensievelabs.org/updates): Bulletins and security advisories, categorised and numbered. Also available as RSS. ## Key documents ### The standard paper: contracts, terms and policies - [MSA-IN-001: Master Services Agreement: India Master](https://trust.pensievelabs.org/documents/msa-in-001-master-services-agreement-india-master): The standard Master Services Agreement (India master), published in full before anyone asks for it, so counsel can raise redlines on day one instead of day twenty. - [DPA-GL-001: Data Processing Agreement](https://trust.pensievelabs.org/documents/dpa-gl-001-data-processing-agreement): Data Processing Agreement: processing details, processor obligations, sub-processing, audit rights, breach clocks, international transfers and deletion on exit. - [SLA-GL-001: Service Level Agreement](https://trust.pensievelabs.org/documents/sla-gl-001-service-level-agreement): Service Level Agreement: availability commitment and how it is measured, response and restoration targets, service credits, and what the SLA cannot cover on hardware Pensieve does not control. - [ADD-GL-001: Security Addendum](https://trust.pensievelabs.org/documents/add-gl-001-security-addendum): Security Addendum: the contractual form of the security controls, written per deployment model rather than as one clause true of none. - [NDA-GL-002: Click-through Mutual Non-Disclosure Agreement](https://trust.pensievelabs.org/documents/nda-gl-002-click-through-mutual-non-disclosure-agreement): The click-through mutual NDA. Acceptance is one click, recorded against the exact rendered hash as evidence; NDA-tier access is then granted by an administrator, target four business hours. - [POL-GL-050: Platform Terms of Service](https://trust.pensievelabs.org/documents/pol-gl-050-platform-terms-of-service): Platform Terms of Service. - [POL-GL-053: Privacy Policy](https://trust.pensievelabs.org/documents/pol-gl-053-privacy-policy): Privacy Policy for Pensieve as a data fiduciary in its own right: this Trust Center, the website and business contact data. Patient data is governed by the DPA, not by this policy. - [POL-GL-059: Vulnerability Disclosure Policy and security.txt](https://trust.pensievelabs.org/documents/pol-gl-059-vulnerability-disclosure-policy-and-security-txt): Vulnerability Disclosure Policy: safe harbour with its honest limits, response and remediation targets by severity, rules of engagement, 90-day coordinated disclosure, and the security.txt contents. - [POL-GL-055: Sub-Processor Notification and Objection Terms](https://trust.pensievelabs.org/documents/pol-gl-055-sub-processor-notification-and-objection-terms): Sub-processor notification and objection terms: notice period, objection window, and what happens if a hospital objects. - [POL-GL-066: Grievance Redressal Policy and Grievance Officer Notice](https://trust.pensievelabs.org/documents/pol-gl-066-grievance-redressal-policy-and-grievance-officer-notice): Grievance redressal policy and the DPDP-mandated Grievance Officer notice. - [POL-GL-067: Legal and Law Enforcement Request Policy](https://trust.pensievelabs.org/documents/pol-gl-067-legal-and-law-enforcement-request-policy): Legal and law-enforcement request policy: how a government request for hospital data is handled, and when the hospital is told. - [ADD-GL-005: Use Case Restrictions and Prohibited Uses](https://trust.pensievelabs.org/documents/add-gl-005-use-case-restrictions-and-prohibited-uses): Use-case restrictions and prohibited uses: what Pensieve may not be deployed to do. - [POL-GL-056: Support Policy and Escalation Matrix](https://trust.pensievelabs.org/documents/pol-gl-056-support-policy-and-escalation-matrix): Support policy and escalation matrix: hours, severities, escalation path and the first-line boundary. - [POL-GL-064: Product End-of-Life and Deprecation Policy](https://trust.pensievelabs.org/documents/pol-gl-064-product-end-of-life-and-deprecation-policy): Product end-of-life and deprecation policy, including notice periods. - [POL-GL-065: Price Change and Renewal Policy](https://trust.pensievelabs.org/documents/pol-gl-065-price-change-and-renewal-policy): Price change and renewal policy, with the escalation cap. - [POL-GL-063: Refund, Credit and Service Credit Policy](https://trust.pensievelabs.org/documents/pol-gl-063-refund-credit-and-service-credit-policy): Refund, credit and service credit policy. - [All 32 public documents in Legal & Contractual](https://trust.pensievelabs.org/documents?family=2): The remaining 16 are listed in the register, unfiltered and ungated. ### Security, privacy and architecture disclosures - [WPR-GL-001: Pensieve Security Whitepaper](https://trust.pensievelabs.org/documents/wpr-gl-001-pensieve-security-whitepaper): The Security Whitepaper. The single document to read first: architecture, controls, isolation, key management, personnel, incident response, and where each control's applicability stops. - [WPR-GL-004: Deployment Models Explained: DM-1 to DM-4](https://trust.pensievelabs.org/documents/wpr-gl-004-deployment-models-explained-dm-1-to-dm-4): Deployment models explained, DM-1 to DM-4, with what each model costs in schedule and money and which one answers a residency requirement absolutely. - [WPR-GL-005: Trust & Assurance Overview: What Pensieve Has, What Is Coming, What It Does Not Have](https://trust.pensievelabs.org/documents/wpr-gl-005-trust-and-assurance-overview-what-pensieve-has-what-is-coming): Trust and assurance overview: what Pensieve has, what is coming with dates and named owners, and what it does not have. Read this before assuming any certification. - [WPR-GL-002: Pensieve Architecture & Technical Overview](https://trust.pensievelabs.org/documents/wpr-gl-002-pensieve-architecture-and-technical-overview): Architecture and technical overview: what the platform is, what it runs on and how a deployment is shaped. - [WPR-GL-003: Data Protection & Privacy Whitepaper](https://trust.pensievelabs.org/documents/wpr-gl-003-data-protection-and-privacy-whitepaper): Data protection and privacy whitepaper: the processor position, lawful basis mapping and privacy architecture. - [DIS-GL-008: Data Residency Statement](https://trust.pensievelabs.org/documents/dis-gl-008-data-residency-statement): Data Residency Statement. Answers all four components (storage, processing, logs and human access) per deployment model and per market, and names the markets where a legal requirement cannot currently be met. - [DIS-GL-009: Subprocessor Register](https://trust.pensievelabs.org/documents/dis-gl-009-subprocessor-register): Sub-processor register: every sub-processor with purpose, data categories, location and the deployment models it applies to. The live version is the API below. - [DIS-GL-011: Encryption Disclosure](https://trust.pensievelabs.org/documents/dis-gl-011-encryption-disclosure): Encryption disclosure: algorithms and key lengths at rest and in transit, and where the keys live in each deployment model. - [DIS-GL-016: Incident Response & Breach Notification Commitment](https://trust.pensievelabs.org/documents/dis-gl-016-incident-response-and-breach-notification-commitment): Incident response and breach notification commitment: severity model, notification timelines to the hospital, to data principals and to regulators, including the CERT-In six-hour clock. - [DIS-GL-024: Integration Boundary Statement](https://trust.pensievelabs.org/documents/dis-gl-024-integration-boundary-statement): Integration Boundary Statement: exactly where Pensieve's responsibility stops and the hospital's begins for every external system, under the BYOK/BYOC model. - [DIS-GL-026: ABDM / NHCX Responsibility Matrix: Sequencing, Owners and Acknowledgement](https://trust.pensievelabs.org/documents/dis-gl-026-abdm-nhcx-responsibility-matrix-sequencing-owners-and): ABDM / NHCX responsibility matrix: who does what, in which order, and what each party acknowledges before go-live. - [DIS-GL-028: Clinical Safety Boundary Statement: Why Pensieve Is Not a Medical Device](https://trust.pensievelabs.org/documents/dis-gl-028-clinical-safety-boundary-statement-why-pensieve-is-not-a): Clinical Safety Boundary Statement: why Pensieve is not a medical device, stated against the applicable rules rather than asserted. - [DIS-GL-027: AI / ML Feature Disclosure](https://trust.pensievelabs.org/documents/dis-gl-027-ai-ml-feature-disclosure): AI / ML feature disclosure: the feature inventory, the training-data position and the human-oversight requirement. - [POL-GL-000: Policy Framework: Index, Ownership, Review Cadence and Control Mapping](https://trust.pensievelabs.org/documents/pol-gl-000-policy-framework-index-ownership-review-cadence-and-control): Policy framework index: every internal policy, its owner, its review cadence and its control mapping. The entry point to the policy set below it. - [DIS-GL-023: Data Deletion & Return Disclosure](https://trust.pensievelabs.org/documents/dis-gl-023-data-deletion-and-return-disclosure): Data deletion and return disclosure: method, verification and the certificate issued on completion. - [DIS-GL-029: Interoperability & Standards Disclosure](https://trust.pensievelabs.org/documents/dis-gl-029-interoperability-and-standards-disclosure): Interoperability and standards disclosure: FHIR, HL7, DICOM and the integration catalogue. - [DIS-GL-030: Uptime, Performance & Capacity Disclosure](https://trust.pensievelabs.org/documents/dis-gl-030-uptime-performance-and-capacity-disclosure): Uptime, performance and capacity disclosure, with the measurement method. - [All 27 public documents in Security, Privacy & Trust Disclosures](https://trust.pensievelabs.org/documents?family=3): The remaining 10 are listed in the register, unfiltered and ungated. ### Assurance and evidence: what exists instead of a certificate - [STM-GL-011: ISO/IEC 27001:2022 Readiness Statement](https://trust.pensievelabs.org/documents/stm-gl-011-iso-iec-27001-2022-readiness-statement): ISO/IEC 27001 readiness statement, with the target date and the named owner. - [STM-GL-012: SOC 2 Readiness Statement](https://trust.pensievelabs.org/documents/stm-gl-012-soc-2-readiness-statement): SOC 2 readiness statement, with the target date and the named owner. - [QRE-GL-005: CSA Consensus Assessments Initiative Questionnaire (CAIQ v4): Self-Assessed](https://trust.pensievelabs.org/documents/qre-gl-005-csa-consensus-assessments-initiative-questionnaire-caiq-v4-self): CSA CAIQ v4, self-assessed and complete. Self-assessed is stated on the face of it. - [STM-GL-026: Uptime History and Status Page Archive](https://trust.pensievelabs.org/documents/stm-gl-026-uptime-history-and-status-page-archive): Uptime history and status page archive, with the publication rules. - [All 5 public documents in Assurance & Evidence](https://trust.pensievelabs.org/documents?family=4): The remaining 1 are listed in the register, unfiltered and ungated. ### Exit, portability and what happens if Pensieve fails - [WPR-GL-400: Exit and Data Portability Commitment](https://trust.pensievelabs.org/documents/wpr-gl-400-exit-and-data-portability-commitment): Exit and Data Portability Commitment. What the hospital gets back, in what format, how fast, at what cost, and what is deleted afterwards, published to neutralise the switching objection before it is raised. - [DIS-GL-401: Data Export Format Specification](https://trust.pensievelabs.org/documents/dis-gl-401-data-export-format-specification): Data export format specification: the exact schema and layout of the export package, so a successor vendor can plan against it today. - [DIS-GL-406: Post-Termination Data Retention Statement](https://trust.pensievelabs.org/documents/dis-gl-406-post-termination-data-retention-statement): Post-termination data retention statement: what is retained after termination, for how long, and why. - [DIS-GL-407: Business Failure Continuity Plan](https://trust.pensievelabs.org/documents/dis-gl-407-business-failure-continuity-plan): Business Failure Continuity Plan: what happens to a hospital's operation if Pensieve ceases to exist. Escrow, release events and the licence on release. ### Jurisdiction variants: India, Australia, EU/EEA, Denmark, Norway, UAE - [DPA-EU-001: Data Processing Agreement: GDPR Article 28 (EU/EEA), with Standard Contractual Clauses Module Two](https://trust.pensievelabs.org/documents/dpa-eu-001-data-processing-agreement-gdpr-article-28-eu-eea-with-standard): Data Processing Agreement under GDPR Article 28 for the EU/EEA, with Standard Contractual Clauses Module Two and the elections made. - [MSA-EU-001: Master Services Agreement: EU/EEA Variant](https://trust.pensievelabs.org/documents/msa-eu-001-master-services-agreement-eu-eea-variant): Master Services Agreement, EU/EEA variant. - [DIS-EU-008: Data Residency Statement: EEA](https://trust.pensievelabs.org/documents/dis-eu-008-data-residency-statement-eea): Data residency statement for the EEA. - [POL-EU-053: Privacy Policy: GDPR Variant (EU/EEA)](https://trust.pensievelabs.org/documents/pol-eu-053-privacy-policy-gdpr-variant-eu-eea): Privacy Policy, GDPR variant for the EU/EEA. - [STM-EU-001: EHDS Readiness Statement: EHR-System Conformity under Regulation (EU) 2025/327](https://trust.pensievelabs.org/documents/stm-eu-001-ehds-readiness-statement-ehr-system-conformity-under-regulation): EHDS readiness statement: EHR-system conformity under Regulation (EU) 2025/327. - [STM-EU-002: NIS2 Supplier Statement: Supply-Chain Security for Essential Entities](https://trust.pensievelabs.org/documents/stm-eu-002-nis2-supplier-statement-supply-chain-security-for-essential): NIS2 supplier statement: supply-chain security commitments for essential entities. - [STM-NO-001: Normen Supplier Conformance Statement: Norwegian Health Sector Information Security and Privacy Norm](https://trust.pensievelabs.org/documents/stm-no-001-normen-supplier-conformance-statement-norwegian-health-sector): Normen supplier conformance statement for the Norwegian health sector. - [STM-NO-002: Norsk Helsenett and HelseID: Supplier Status and National Service Integration](https://trust.pensievelabs.org/documents/stm-no-002-norsk-helsenett-and-helseid-supplier-status-and-national): Norsk Helsenett and HelseID supplier status and national service integration. - [DIS-DK-001: Danish Cloud Position and Supervisory Response](https://trust.pensievelabs.org/documents/dis-dk-001-danish-cloud-position-and-supervisory-response): Danish cloud position and the supervisory response it was written against. - [STM-DK-002: Danish National Health Infrastructure: Integration Status and Gate Analysis](https://trust.pensievelabs.org/documents/stm-dk-002-danish-national-health-infrastructure-integration-status-and): Danish national health infrastructure: integration status and gate analysis, including MedCom. - [DIS-AE-008: Data Residency & Localisation Statement: United Arab Emirates](https://trust.pensievelabs.org/documents/dis-ae-008-data-residency-and-localisation-statement-united-arab-emirates): Data residency and localisation statement for the United Arab Emirates, including the health-data localisation rule. - [STM-AE-001: Information Assurance Statement: United Arab Emirates](https://trust.pensievelabs.org/documents/stm-ae-001-information-assurance-statement-united-arab-emirates): Information assurance statement for the United Arab Emirates. - [All 19 public documents in Jurisdiction Variant Sets](https://trust.pensievelabs.org/documents?family=14): The remaining 7 are listed in the register, unfiltered and ungated. ### Corporate and entity - [STM-GL-028: Company Profile: Corporate Overview](https://trust.pensievelabs.org/documents/stm-gl-028-company-profile-corporate-overview): Company profile and corporate overview: who the counterparty actually is. - [STM-IN-018: MSME Status Declaration and 45-Day Payment Notice](https://trust.pensievelabs.org/documents/stm-in-018-msme-status-declaration-and-45-day-payment-notice): MSME status declaration and the MSMED 45-day payment notice, which changes a hospital's payment obligation. - [STM-GL-030: Anti-Bribery and Anti-Corruption Declaration](https://trust.pensievelabs.org/documents/stm-gl-030-anti-bribery-and-anti-corruption-declaration): Anti-bribery and anti-corruption declaration. - [STM-GL-031: Modern Slavery and Ethical Sourcing Statement](https://trust.pensievelabs.org/documents/stm-gl-031-modern-slavery-and-ethical-sourcing-statement): Modern slavery and ethical sourcing statement. - [STM-AU-031: Modern Slavery Statement: Australia (Voluntary)](https://trust.pensievelabs.org/documents/stm-au-031-modern-slavery-statement-australia-voluntary): Modern slavery statement for Australia, published voluntarily below the reporting threshold. - [All 8 public documents in Corporate & Entity](https://trust.pensievelabs.org/documents?family=1): The remaining 3 are listed in the register, unfiltered and ungated. ### How this Trust Center governs itself - [POL-GL-500: Trust Center Access Policy, Document Classification & Publication Policy](https://trust.pensievelabs.org/documents/pol-gl-500-trust-center-access-policy-document-classification-and): Trust Center Access Policy: the tiering doctrine. The default is public; a gate must be justified because every gate costs days. This is the document that explains why so much is ungated. - [POL-GL-501: Document Classification & Publication Policy](https://trust.pensievelabs.org/documents/pol-gl-501-document-classification-and-publication-policy): Document classification and publication policy: how a document's tier is decided. - [POL-GL-510: Watermarking & Leak-Tracing Notice](https://trust.pensievelabs.org/documents/pol-gl-510-watermarking-and-leak-tracing-notice): Watermarking and leak-tracing notice: what is embedded in a gated render and why. - [All 5 public documents in Trust Center Meta](https://trust.pensievelabs.org/documents?family=15): The remaining 2 are listed in the register, unfiltered and ungated. ### Notice formats - [NTC-GL-021: Security Bulletin: Standard, Format and Template](https://trust.pensievelabs.org/documents/ntc-gl-021-security-bulletin-standard-format-and-template): Security bulletin standard and template: the fixed Summary / Background / Details / Remediation structure every advisory follows, and the numbering scheme. - [All 3 public documents in Notices](https://trust.pensievelabs.org/documents?family=11): The remaining 2 are listed in the register, unfiltered and ungated. ### People, labour and internal governance - [POL-IN-305: Code of Conduct and Ethics](https://trust.pensievelabs.org/documents/pol-in-305-code-of-conduct-and-ethics): Code of Conduct and ethics. - [POL-IN-306: Prevention of Sexual Harassment at the Workplace (POSH) Policy and Internal Committee Constitution](https://trust.pensievelabs.org/documents/pol-in-306-prevention-of-sexual-harassment-at-the-workplace-posh-policy): POSH policy and the Internal Committee constitution, as required in India. - [All 4 public documents in People, Labour & Internal Governance](https://trust.pensievelabs.org/documents?family=12): The remaining 2 are listed in the register, unfiltered and ungated. ## Positioning pages - [Deployment models](https://trust.pensievelabs.org/deployment-models): DM-1 to DM-4 compared, including which one breaks the 14-day timeline and why that is said out loud. - [Interoperability, ABDM, NHCX and BYOK](https://trust.pensievelabs.org/interoperability): Where Pensieve deliberately is not the regulated participant, and how the hospital's own credentials are used on the hospital's own authority. - [Sub-processors](https://trust.pensievelabs.org/subprocessors): The live register with a change feed and advance notification. - [Exit and portability](https://trust.pensievelabs.org/exit): What a hospital gets back, in what format and how fast. - [Commercial framework](https://trust.pensievelabs.org/commercial): The two-clock commercial model: a fixed platform fee payable in advance, plus a value share measured in arrears. No prices. - [Security questions, answered](https://trust.pensievelabs.org/faq): The standard security-review questions, answered with a citation to a document ID and section. - [Status](https://trust.pensievelabs.org/status): Availability, per deployment model, including the plain statement that DM-4 availability is outside Pensieve's control. - [Evidence pack](https://trust.pensievelabs.org/evidence-pack): One download containing every public document as both Markdown and HTML, with a manifest of SHA-256 hashes and a triage README. - [Vulnerability disclosure](https://trust.pensievelabs.org/security-policy): How to report something you find, what happens next and by when. - [How the register works](https://trust.pensievelabs.org/register): The five classification axes, the tier ladder and what each gate costs in time. ## Machine-readable surfaces - [/llms.txt](https://trust.pensievelabs.org/llms.txt): This file. - [/trust-manifest.json](https://trust.pensievelabs.org/trust-manifest.json): Machine-readable posture: entity identity, deployment models with controller and processor posture, sub-processors with jurisdictions, residency claims, an explicitly empty certifications array, assurance artefacts and the API index. - [/updates.rss](https://trust.pensievelabs.org/updates.rss): RSS 2.0 feed of every bulletin and security advisory. - [/sitemap.xml](https://trust.pensievelabs.org/sitemap.xml): Every public route and every public document. - [/.well-known/security.txt](https://trust.pensievelabs.org/.well-known/security.txt): RFC 9116 contact, policy and expiry. - [GET /api/public/documents](https://trust.pensievelabs.org/api/public/documents): The public tier as JSON. Filter by family, kind, jurisdiction, dm and q; page with limit and offset. - [GET /api/public/documents/{slug}](https://trust.pensievelabs.org/api/public/documents/dis-gl-008-data-residency-statement): One document as rendered HTML with its last-modified date, SHA-256 and full classification. - [GET /api/public/subprocessors](https://trust.pensievelabs.org/api/public/subprocessors): The live sub-processor register. - [GET /api/public/updates](https://trust.pensievelabs.org/api/public/updates): Bulletins as JSON. - [GET /api/public/policies/{slug}](https://trust.pensievelabs.org/api/public/policies/pol-gl-053-privacy-policy): A policy body for embedding, addressable by slug, document ID or the marketing path it is the source of truth for. ## Citing this material Every document carries a stable document ID (`WPR-GL-001`), a semantic version, a `Last Modified On` date, a review-due date and a SHA-256 of its body. Quote the document ID and the date. Any hash resolves at https://trust.pensievelabs.org/verify/{hash}, which is the way to check that a quoted passage is the current text rather than a stale copy. Correspondence: info@pensievelabs.org for security review and vulnerability reports; info@pensievelabs.org for privacy, DPDP and GDPR; info@pensievelabs.org for contracts and redlines. This site loads no third-party script, no analytics tag and no external font, which is verifiable from the network tab.