// Trust
Plain answers about your data.
Synthetic data only
Standard reviews run against a staging copy with synthetic accounts and fixtures. We don't read or write real employee or customer records.
Read-only source access
Optional. A read-only GitHub App or immutable snapshot covering one repository and one commit, with minimum permissions. Revocable at any time.
Evidence handling
Evidence is stored per tenant and redacted in shared views. Support staff see metadata by default, not raw evidence.
AI model subprocessors
General-purpose models help analyze and write, grounded on evidence objects. Subprocessors and data terms are listed in our DPA before you authorize.
Retention
Credentials and test tokens are revoked at engagement end. Evidence retention follows the period set in your rules of engagement.
Private by default
Readiness reports are shared only with collaborators you authorize. Liquid issues no public site-secure seal and no public verification URL.
Security contact: security@liquid.example (placeholder until launch).