Demystify Systems logoDemystifySystems
Trust & security

How Demystify earns trust

No badge wall — we hold no certifications and we won't invent any. What we have is architecture you can check yourself: isolation at the database, your own AI keys, ledgers you can verify, and tools that keep working with the internet off.

The practices

Architecture facts, not badges

Six things about how the products are built. Every line below is a claim we already ship elsewhere on this site — nothing here was written specially for a trust page.

  • Row-level isolationAvailable

    Per-company isolation with Postgres row-level security across every product.

    Roles are enforced at the database with row-level security and audit logging — not just in the UI.

  • Bring your own AI keysAvailable

    Bring your own AI keys — no token markup, no lock-in, nothing to leak.

    The BYOK gateway spans 35+ providers with fallbacks and per-agent budget caps.

  • Signed, append-only ledgersAvailable

    Signed, append-only records — verify them yourself, don't take our word.

    Append-only, signed and tamper-evident ledgers you can verify, not just trust.

  • AI kill switch & default-deny approvalsAvailable

    Budgets, default-deny approvals, a tamper-evident audit chain — and one tap to stop it all.

    Every agent action passes one gate: kill switch → pause → policy → autonomy floors → default-deny approval. Payments and deletes always need a human.

  • Offline-first, no upload pathAvailable

    269 of our 287 free tools run entirely in your browser — nothing uploads, no ads, no fingerprinting.

    Don't take our word for it: turn off your internet and watch them keep working.

  • Export any dayAvailable

    Exportable any day, in formats you already use — no lock-in, no ransom.

    If we ever disappoint you, leaving is a download, not a negotiation.

Where we stand

The honest status of compliance

The same sentence our footer prints on every page — here with the room to say exactly what it does and doesn't mean.

GDPR · UK GDPR · CCPA · India DPDP-aligned — row-level security · SOC 2 on the roadmap

SOC 2 — on the roadmap

On the roadmap

That chip is the whole claim: on the roadmap. Not certified, not compliant — and this page will not say either word until an independent auditor has done their work. In the meantime, the controls an audit would examine are the cards above: row-level security at the database, roles with audit logging, and signed ledgers you can verify without asking us.

GDPR · UK GDPR · CCPA · India DPDP

We say aligned — deliberately. “Certified” or “compliant” would imply an external attestation we don’t hold, so we don’t use those words. What aligned looks like in practice is on this page and in our privacy policy.

Responsible disclosure

Found something? Tell us.

If you believe you've found a security issue in any Demystify product or on this site, we want to hear about it before anyone else does.

Email hello@demystifysystem.com with the subject line “Security disclosure” and enough detail to reproduce what you found. Please give us a reasonable window to fix the issue before disclosing it publicly.

Being honest, as everywhere on this site: we don’t run a bug bounty programme today, so we can’t promise a reward. We can promise a human reads every report — we typically reply within one business day.

Report a security issue
Own Your SystemsGoverned AI AgentsASHR.work · PeopleFinocket · MoneyMysty Pie · IntelligenceTechnology ConsultingProduct EngineeringData & IntegrationsAWS · GCP · AzureCloud ModernizationManaged OperationsWorkflow AutomationCustom SoftwareDecode · Design · Deliver