liquid://

// Trust

Plain answers about your data.

Liquid only operates where it has been explicitly authorized, and tells you exactly what it touched.

Synthetic data only

Standard reviews run against a staging copy with synthetic accounts and fixtures. We don't read or write real employee or customer records.

Read-only source access

Optional. A read-only GitHub App or immutable snapshot covering one repository and one commit, with minimum permissions. Revocable at any time.

Evidence handling

Evidence is stored per tenant and redacted in shared views. Support staff see metadata by default, not raw evidence.

AI model subprocessors

General-purpose models help analyze and write, grounded on evidence objects. Subprocessors and data terms are listed in our DPA before you authorize.

Retention

Credentials and test tokens are revoked at engagement end. Evidence retention follows the period set in your rules of engagement.

Private by default

Readiness reports are shared only with collaborators you authorize. Liquid issues no public site-secure seal and no public verification URL.

Security contact: security@liquid.example (placeholder until launch).