gothink software runs inside your boundary and no document ever leaves it. No certification has been issued yet — this page says where each one stands, and ships the subprocessor list, DPA draft, data-flow diagram and your questionnaire completed. Ask, and it arrives as a document, not a meeting.
If a claim here cannot be demonstrated on demand, it should not be here.
Click a field and land on the source page; anything below your threshold abstains into the exception queue and waits for a named approver.
See the gate and the lineage YoursYour configuration, calibration, ground truth and corrections are readable files you keep, and export as a training set for a model you own — nothing switches off if you do not renew.
Read the ownership schedule ScoredTwenty-five of your documents, labelled by your experts, scored on six published measures — a figure we did not produce and cannot tune, and a method you can run against every vendor on your shortlist.
Score your documentsOn gothink Cloud your data stays in your tenant and region; inside your boundary nothing leaves at all, and nothing you run trains anything of ours. SOC 2 is not yet issued — our status, subprocessor list and DPA are on request.
Trust Center Who approvesEvery automated action above your threshold waits, states what will change, and asks.
Autonomy & gates How it startsSchema mapping, gates, ground truth labelled by your experts, then a pilot gate you can walk away at.
How onboarding runsSigned release bundles installed in your VPC, on-prem or air-gapped environment under your IAM and keys.
No page, no field, no metadata, no usage telemetry. The runtime has no network dependency on gothink to operate or to validate its licence.
Extraction runs on models deployed in your boundary. Where you choose to use an external model, it is your account, your contract and your decision, and it is off by default.
Licence state is a signed file with an expiry, installed alongside the runtime. Renewal is a new file, delivered like any offline release bundle.
Steward corrections retrain extractors inside your deployment. Nothing you process is used to train gothink's models or any other customer's.
Masking and entitlements are applied before anything is indexed or served, so downstream RAG and agents inherit your access rules.
Nothing below is issued yet. Here is each item, its real status, and the document you can have meanwhile — updated the day a status changes, not the quarter after.
| Item | Status | What you can have now | Scope |
|---|---|---|---|
| SOC 2 Type I | Not yet issued — readiness plan written, auditor not yet engaged | The readiness plan and a description of the controls in place, on request | gothink corporate environment, release pipeline and support processes |
| SOC 2 Type II | Not yet issued — no observation window open | The same controls description; we will tell you the day a window opens | Same scope, observed over a period once started |
| ISO/IEC 27001 and 42001 | Not certified | The control library mapping, on request | Information security and AI management systems |
| GDPR / UK GDPR | Applies by design | — | gothink processes no customer personal data in its own systems; the runtime processes it in yours |
| HIPAA-eligible deployment | Supported | BAA available where gothink is a processor | PHI never leaves the customer boundary; masking at the govern stage |
| Penetration test | None performed yet — scope written, tester not yet appointed | The test scope document, on request | Runtime, control plane and release pipeline |
| DPA and subprocessor list | In preparation | The current draft, on request | Processing terms and gothink's own subprocessors |
| SBOM and release checksums | Available | With every release | Runtime image and release bundles |
A Type II cannot be shortened — it needs a real observation window, and any vendor claiming otherwise is describing a Type I. We will not imply that window has started when it has not.
Ask for the controls description — control by control against the SOC 2 criteria, written for your security team. The stronger argument meanwhile is architectural: at Enterprise and Sovereign the runtime executes inside your boundary, under your IAM, on your keys — the certification covers our corporate environment, and your documents were never in it.
Send us yours and it comes back completed rather than scheduled. We do not yet publish a pre-filled CAIQ.
Request the questionnaireBoth are in preparation and with counsel. Ask for the current draft, and note that on in-boundary deployment no subprocessor sees a page of your data.
Request the DPAWhat crosses inward, what never crosses outward, and where every credential lives. The same diagram your architects will draw on.
Architecture referenceControl by control against the SOC 2 criteria, for the period before any report is issued, alongside the readiness plan.
Request the controls descriptionNo test has been performed yet. The scope we intend to commission is written and available; there is no summary to share.
Request the scopeA draft term sheet for source escrow on Enterprise and Sovereign, released on defined trigger events. No agent is appointed yet. Because a small vendor should expect to be asked.
Ownership and escrowOwnership claims are usually about weights on the vendor’s infrastructure under a licence nobody checked for transferability. Here are the answers to the three questions your architects will ask.
The base model is named in your order-form schedule, not described as “a leading open model”. gothink warrants its licence permits the derivative weights to transfer to you and run without gothink; any base model that cannot support that is not eligible for the runtime.
Standard open weight files with tokenizer and config, adapter weights where tuning is adapter-based, and records and lineage as documented schemas — no proprietary container. If your team can load a public model, they can load this.
Open weights are served by several independent inference providers and on your own hardware, so portability is demonstrable, not promised. On request we will run your exported weights outside gothink’s software, before you sign. An ownership claim never tested is a marketing claim.
“Nothing you run trains our models” raises a fair question. The answer: we learn from the pipeline’s own behaviour, not from what passed through it — an auditable distinction.
| Category | Leaves your boundary? | What happens to it |
|---|---|---|
| Documents, pages, images | Never | Processed in place. Not transmitted, not retained by gothink, not available to gothink staff |
| Extracted values and records | Never | Written to your systems under your retention policy |
| Tuned weights and steward corrections | Never | Retrain your extractors inside your deployment. Yours permanently |
| Your eval set and its scores | Never | Used to certify your accuracy floor. Not aggregated, not benchmarked against other customers |
| Pipeline behaviour signals | Only with consent | Which field types abstain most often, which layout structures defeat a classifier, which confidence thresholds later produced corrections, which schema shapes needed amendment after a regulatory change. Counts and categories, never content |
If a clause layout defeats the classifier at one firm, the shape of that failure informs the next pack release. Every customer gets the improvement; none gets another customer’s documents, values or model.
Behaviour signals are off unless you switch them on, per deployment; turning them off later changes nothing about your accuracy floor or support. The signal schedule is an annex to the DPA, not a privacy-policy paragraph.
The signal payload is written to a local log before transmission, in the clear, so your security team can read exactly what would leave and block it at the network layer if they disagree. We would rather you verified this than believed it.
Because the runtime is in your boundary, the subprocessor list for customer data is empty. The list below covers gothink's own corporate operations only.
| Purpose | Subprocessor | Customer documents or fields? |
|---|---|---|
| Customer documents, fields, lineage, weights | None | Never leaves your boundary |
| Support ticketing and email | Named in the DPA pack | No — correspondence only |
| Source hosting and release signing | Named in the DPA pack | No — gothink code only |
Every release is a signed bundle with an SBOM. Air-gapped deployments receive the same bundle by the channel agreed at onboarding.
Security patches for the current and previous major version. End-of-support dates are published twelve months ahead.
Support policyReport a vulnerability and we acknowledge within two business days, triage within five, and notify affected licensees with a patch or mitigation.
gothink engineers use accounts you provision and revoke, with your logging. There is no standing access after onboarding unless an operations tier requires it.
Independent testing of the runtime and control plane is scoped and intended per major release. The first test has not been commissioned.
The contracting entity, its jurisdiction of incorporation and its registration number are stated on the order form and in the DPA pack, both available on request before any commercial conversation.
It comes back completed, alongside the architecture reference and the compensating controls document. The runtime never asks you to trust a promise the topology does not already enforce.
Twenty-five documents from your own estate, labelled by your own experts. Free, no contract, and you keep the report either way.
Schema mapping, confidence gates and a ground-truth set, at a fixed price with a fixed end date. Exit at the pilot gate having paid the first milestone only.
Go live on the licence with the tuned weights handed over. Releases, packs and support carry on from there.