Trust Center
Safety, privacy and the right to correct
Trust comes from visible limits, named owners and verifiable corrections—not a promise that everything is under control.
Content state: draft Owner: owner:security-privacy Next review: 2026-09-07
Privacy by default
The candidate uses synthetic and public metadata-onlyA safe boundary showing an owner, URL, version, coverage or status without exposing the content itself. material. Private cases, documents, contacts and exact addresses stay in a separate plane.
- No visitor tracking, cookies or advertising profiles.
- Minimisation and retentionThe approved time and conditions before material is deleted, archived or placed on legal hold. are named before data is admitted.
- Personal data does not move to QazLake, QazCompute or an AI provider without a separate legal and consentA person's voluntary agreement after understanding the purpose, risks and how to withdraw it. basis.
Security and abuse
High-risk capabilities are disabled: active collection, SSRFA vulnerability class where an attacker causes a server to request an internal, local or otherwise forbidden address. execution, biometrics, cross-organisation search and autonomous publication.
- Every future connector gets an owner, kill switchA control that immediately disables a connector or risky capability and prevents unauthorized reactivation. and threat modelA structured description of assets, adversaries, attack paths, impact and controls..
- Abuse and incident reports go to a named owner; there is no public emergency chat.
- Fail-closed is more important than demo convenience.
Corrections and transparency
The correction logAn append-only record of a material change, its date, reason and new version., changelog and status page separate local checks from production and public proof.
- Report an error through an owner-gated channel without publishing sensitive data.
- Date and version every material change.
- An internal review never publishes a public case automatically.