Trust and data protection
Last updated 30 August 2026
This is the public index for how ConformOps handles customer material. The pages below are crawlable, listed in the sitemap, and written against the implemented data flows. They avoid an EU-only, zero-retention, or no-human-access claim that the current deployment cannot prove.
Optional AI processing
The workspace and product controls, what OpenAI receives, the no-training boundary, and what store: false does and does not mean.
Data processing agreement
The Article 28 terms, processing instructions, security measures, subprocessors, assistance, audit information, and deletion obligations.
Data residency
Current production placement, global processing boundaries, third-country transfers, and the explicit absence of an EU-only guarantee.
Breach notification commitment
When and how ConformOps will notify a customer about a personal-data breach affecting customer data, and what the notice will contain.
Account and product deletion
The difference between archive and permanent erasure, confirmation safeguards, cross-store verification, and records that must remain.
Backups and recovery
D1: The production database uses Cloudflare's production storage backend, where provider-managed Time Travel supplies point-in-time recovery within the plan's retention window. ConformOps relies on that facility; an operator initiates an in-place restore. There is no separate scheduled ConformOps D1 export today.
R2: ConformOps relies on Cloudflare's replicated durability for infrastructure failure. The current production bucket has no bucket-lock rule, ConformOps-managed versioned recovery copy, or separate backup. R2 durability does not undo an accidental deletion or overwrite. An object must be rebuilt from still-authorised retained inputs where possible, or supplied again by the customer.
Restoration status: ConformOps has not yet completed and recorded a production restoration exercise, so it does not publish an RTO or RPO. After accidental D1 deletion or corruption, the service stays unavailable while the operator selects and verifies a restore point.
Erasure wins over recovery: A restored database is not returned to service until erasure requests later than the restore point have been reapplied and verified. If that journal cannot be shown complete, the restored state is not used. Deleted R2 customer objects are not recovered from a separate copy because no such copy is kept.
Short version
- OpenAI is the only AI provider. Workspace and product controls are off by default, both must be on, and only an Owner or Admin can change them. ConformOps does not opt in to OpenAI API model training.
- Raw archives are extracted in the browser and not retained, repository code is not executed, and detected confidential secrets are redacted before durable storage, indexing, or an optional model call.
- Oversized evidence-relevant files are disclosed as partial coverage. Aggregate repository limits refuse the ingestion instead of silently selecting a smaller subset.
- ConformOps does not sell customer material. Service providers receive only the data needed for the selected service path.
- The current production deployment is not represented as EU-only. The residency page names the verified placement and the remaining global boundaries.
- Product and account erasure use resumable, verified cross-store procedures rather than a database-only delete.
- D1 has provider-managed point-in-time recovery; R2 currently has durable storage but no ConformOps-managed undelete or separate backup.