How Demystify earns trust
No badge wall — we hold no certifications and we won't invent any. What we have is architecture you can check yourself: isolation at the database, your own AI keys, ledgers you can verify, and tools that keep working with the internet off.
Architecture facts, not badges
Six things about how the products are built. Every line below is a claim we already ship elsewhere on this site — nothing here was written specially for a trust page.
- Row-level isolationAvailable
Per-company isolation with Postgres row-level security across every product.
Roles are enforced at the database with row-level security and audit logging — not just in the UI.
- Bring your own AI keysAvailable
Bring your own AI keys — no token markup, no lock-in, nothing to leak.
The BYOK gateway spans 35+ providers with fallbacks and per-agent budget caps.
- Signed, append-only ledgersAvailable
Signed, append-only records — verify them yourself, don't take our word.
Append-only, signed and tamper-evident ledgers you can verify, not just trust.
- AI kill switch & default-deny approvalsAvailable
Budgets, default-deny approvals, a tamper-evident audit chain — and one tap to stop it all.
Every agent action passes one gate: kill switch → pause → policy → autonomy floors → default-deny approval. Payments and deletes always need a human.
- Offline-first, no upload pathAvailable
269 of our 287 free tools run entirely in your browser — nothing uploads, no ads, no fingerprinting.
Don't take our word for it: turn off your internet and watch them keep working.
- Export any dayAvailable
Exportable any day, in formats you already use — no lock-in, no ransom.
If we ever disappoint you, leaving is a download, not a negotiation.
The honest status of compliance
The same sentence our footer prints on every page — here with the room to say exactly what it does and doesn't mean.
GDPR · UK GDPR · CCPA · India DPDP-aligned — row-level security · SOC 2 on the roadmap
SOC 2 — on the roadmap
On the roadmapThat chip is the whole claim: on the roadmap. Not certified, not compliant — and this page will not say either word until an independent auditor has done their work. In the meantime, the controls an audit would examine are the cards above: row-level security at the database, roles with audit logging, and signed ledgers you can verify without asking us.
GDPR · UK GDPR · CCPA · India DPDP
We say aligned — deliberately. “Certified” or “compliant” would imply an external attestation we don’t hold, so we don’t use those words. What aligned looks like in practice is on this page and in our privacy policy.
Found something? Tell us.
If you believe you've found a security issue in any Demystify product or on this site, we want to hear about it before anyone else does.
Email hello@demystifysystem.com with the subject line “Security disclosure” and enough detail to reproduce what you found. Please give us a reasonable window to fix the issue before disclosing it publicly.
Being honest, as everywhere on this site: we don’t run a bug bounty programme today, so we can’t promise a reward. We can promise a human reads every report — we typically reply within one business day.
Report a security issue