Skip to content

Site search

Type to search Pages

Trust centre

Written for the person who signs off on using PathWolf.

This is where your data lives, who processes it, how consent is enforced, what a person approves before anything sends — and the certifications we do not hold.

Hosting

Where your records live.

Data location and hosting, stated plainly so a reviewer can verify it.

A dedicated database

Records are stored in a Neon Postgres database provisioned for this venture alone — not a shared, multi-tenant store.

Hosted on Netlify

The website and its delivery run on Netlify. Traffic between a browser and the service is encrypted in transit.

One codebase, one rulebook

The mobile and desktop applications are built from the same code and rules as the website, and reach the same authenticated endpoints.

Kept deliberately small

Personal data reaches a short, named set of providers and no others; that list is published for you to check, not offered only on request.

Sub-processors

The providers that touch your data.

These named sub-processors, and no others, process personal data. Each one has a single, stated job.

Netlify

Hosts the website and delivers it to the browser.

Neon

Runs the managed Postgres database this site stores its records in.

Resend

Delivers transactional email, such as replies to an enquiry you send us.

Plausible Analytics

Measures usage without cookies and without identifying any visitor.

Cloudflare

Runs Turnstile anti-abuse checks on public forms.

Consent and abuse

Consent enforced, the inbox respected.

How consent is applied, and how a person stays in front of every send.

Consent by category

Cookie consent is enforced by category. Usage measurement loads only after consent and identifies nobody.

No tracking cookies

No advertising or cross-site tracking cookies are set at any point.

Person, not bot

Public forms are protected by Cloudflare Turnstile, which tells a person from a bot without profiling the visitor.

Signed off before it sends

No sequence leaves the system until a named person has approved its target list, message and sending domain.

What we hold, and what we do not.

This page is for the person who has to approve PathWolf before it touches your accounts. It states what is in place today and what is not, with the documents that back each claim. Vagueness reads as absence, so where something does not exist we say so.

Certifications and guarantees

PathWolf holds no SOC 2, no ISO 27001 and no other security certification, and has commissioned no independent audit or penetration test. We publish no availability guarantee, no uptime figure and no service-level commitment, and we run no paid bug-bounty programme.

What exists instead is a short, named set of sub-processors, consent enforced by category, deliverability protected by design, and a published route for reporting a vulnerability. We would rather state that than imply a posture we cannot evidence.

Accessibility

The interface is built to WCAG 2.1 AA: semantic structure, full keyboard operability, visible focus, dialogs that trap and then restore focus, and honoured reduced-motion settings. No independent accessibility audit has been commissioned; our Accessibility Statement records what has and has not been verified.

Reporting a vulnerability

There is a published route for reporting a security vulnerability. It sets out what is in scope, what good-faith research means here, and what a reporter can expect in return. We offer no reward for disclosure; we do commit to a considered reply, and a named person owns the response.

Your data, on request

A person can ask what personal data is held about them, ask for it to be corrected, and ask for it to be deleted. Business customers can obtain data-processing terms before any customer data is processed. Both routes are set out in the documents below.

Security review

The questions a review actually asks.

Where is our data stored?

Records live in a Neon Postgres database provisioned for this venture alone, not a shared store. The site is hosted on Netlify, and traffic between a browser and the service is encrypted in transit.

Who processes our data besides you?

A published set of named sub-processors and no others: Netlify for hosting, Neon for the database, Resend for transactional email, Plausible for cookieless measurement, and Cloudflare for form anti-abuse. The list is published rather than offered on request.

Which security certifications do you hold?

None. PathWolf holds no SOC 2, no ISO 27001 or equivalent, and has run no independent audit or penetration test. What we can show is a short sub-processor list, category-based consent, and a published vulnerability route.

What happens if a security problem is found?

There is a published disclosure route setting the scope, good-faith terms and what a reporter can expect. A named person owns the response. There is no paid reward for disclosure.

Can we get data-processing terms before you handle our data?

Yes. Business customers can obtain data-processing terms before any customer data is processed, and the Privacy Policy sets out the rights an individual can exercise over their own data.

What do your AI colleagues do without a person present?

They cannot send outreach outside approved parameters, and cannot add contacts that fail the agreed criteria. Anything outside bounds is blocked and escalated to the accountable person rather than executed.

Do you set tracking or advertising cookies?

No. Usage measurement is cookieless, identifies nobody, and loads only after consent. No advertising or cross-site tracking cookies are set, and consent is enforced by category.

Ask the questions a review needs answered.

Send your security or data-protection questions and request data-processing terms. A named person answers.