TRUST / CURRENT DISCLOSURES

Trust starts with precise claims.

This center groups the public evidence available today and states where Working Machines does not yet publish a certification, contractual document, or independent assurance report.

Security model

Credential isolation, guarded egress, runtime policy, and confirmation boundaries.

Privacy

Tool data paths, model context, execution records, and user responsibilities.

Runtime status

Canonical health endpoint, expected authorization behavior, and troubleshooting.

Developer documentation

OAuth, MCP, HTTP API, action discovery, and execution guidance.

Terms of Service

Public hosted-service terms, acceptable use, billing, and third-party boundaries.

Responsible disclosure

A dedicated private form and safe-testing guidance for suspected vulnerabilities.

Disclosure matrix

DISCLOSURE PUBLIC STATUS
Security architecture and credential boundaryPUBLISHED
Privacy and model-context behaviorPUBLISHED
Runtime health endpointPUBLISHED
MCP and OAuth discovery metadataPUBLISHED
Public hosted-service termsPUBLISHED
Responsible disclosure policy and private reporting formPUBLISHED
Independent SOC 2 reportNOT CLAIMED
Published ISO 27001 certificationNOT CLAIMED
Public penetration-test reportNOT CLAIMED
Public DPA and subprocessor listNOT CLAIMED
Public SLA and incident-history archiveNOT CLAIMED

“Not claimed” means this website does not currently provide evidence for that assurance. It does not imply that a private customer agreement contains or lacks a particular term. Prospective customers should request the applicable commercial and security documentation through the platform.