Skip to content
Configure →
Trust package

Evidence for procurement, not promises.

Owning the AI system still requires clear documentation: processing roles, technical measures, deletion evidence, update boundaries, model provenance, and a published security contact.

Downloadable briefs
03
Review areas
08
Disclosure channel
01
01 — Status

Controls you can inspect.

Eight defined areas replace broad trust claims with reviewable records, operational templates and published contact routes.

Available now
01 / 08

GDPR / DPA pack

Controller and processor roles, sub-processors, transfer safeguards, and a data processing agreement for business customers.

Available now
02 / 08

TOMs

Technical and organisational measures covering access, encryption, logging, backups, provisioning, and incident response.

Available now
03 / 08

Retention policy

Defined retention periods for order records, support material, logs, and optional Pre-Load files.

Available now
04 / 08

Deletion certificate

Written confirmation when customer files are removed from provisioning storage after an agreed Pre-Load.

Operational template
05 / 08

Model provenance

Model family, source, licence, workload, runtime, format, update channel, and available verification references.

Operational template
06 / 08

Update policy

Separate stable, balanced, and fast-track channels for security, compatibility, and model updates.

Operational template
07 / 08

security.txt

A machine-readable disclosure contact at /.well-known/security.txt linked to the current security policy.

Operational template
08 / 08

Vulnerability policy

A published route for reporting, triage, remediation, customer impact assessment, and disclosure handling.

02 — Provenance

Delivered Model Provenance Card

For configured systems, the customer-facing trust package can include a concise record of what model stack was selected and why it is appropriate for the device.

  1. 1Source repository, model card, publisher, release date, and license posture.
  2. 2Runtime and format: Ollama, llama.cpp, MLX, vLLM, GGUF, Safetensors, or another selected path.
  3. 3Intended workload, known limitations, language fit, and benchmark references used during selection.
  4. 4Checksum or verification reference where available, plus the selected stable, balanced, or fast-track update channel.
03 — Documents

Procurement documents

Versioned, plain-language summaries for an initial technical, security, and privacy review.

Status

This page describes the trust package selbsai maintains for customers. Customer-specific DPA and TOM documents are provided during business onboarding where required.

Trust packagesecurity@selbsai.com
Trust, provenance, and operating policies | selbsai