Public website boundary
The public marketing site does not accept RFQ uploads. A product evaluation begins through an agreed, private workflow rather than an anonymous file-upload form.
Security and data handling
Industrial requests can contain proprietary specifications, pricing and supplier information. Sorsivo treats security as a deployment decision backed by evidence—not a generic badge on a marketing page.
Published operating principles
The public marketing site does not accept RFQ uploads. A product evaluation begins through an agreed, private workflow rather than an anonymous file-upload form.
The product architecture binds private records and operations to an authenticated organization. Customer-specific access and denial evidence are verified for the deployment being evaluated.
Sorsivo prepares work for review. Supplier messages, customer communication, technical equivalence and customer-facing prices require accountable human approval.
Sorsivo does not assume permission to train on customer data. Model providers, processing regions, retention behavior and permitted uses are documented in the implementation scope.
Retention, export and deletion requirements are agreed before live customer data is introduced and then verified against the selected deployment environment.
Sorsivo does not claim SOC 2, ISO 27001 or another certification it has not earned. Security evidence is supplied for the exact implementation and deployment boundary under review.
Current assurance boundary
Sorsivo's repository contains security, tenant-isolation, approval and operations controls. Production assurance still requires evidence from the exact deployed release, providers and customer configuration. We distinguish implemented controls from live verification.
Before implementation