Trust at Rosie

Document Metadata
View in Reference Graph
Title
Trust at Rosie
Description
How Rosie governs its own software, data, and operations β€” software bill of materials and license gate, data protection, tamper-evident verification, and fair commercials. We hold ourselves to the standard we offer our partners.
Status
published 2026-06-27 03:55
Access Level
0
Vector Action
updated
Tags
about
Suggest Prompt
How does Rosie govern its own software and data?

(log in required)
Loading...
Loading vector metadata...

Trust at Rosie

We hold ourselves to the standard we offer our partners.

Rosie is governance infrastructure for professional networks β€” a way to make verified knowledge defensible, attributable, and auditable. This page summarizes how Rosie governs its own software, data, and operations. Detailed documentation is available to partners and their advisors on request.

How your data is handled

Rosie is built so that access, data classification, and disclosure are structural, not afterthoughts. Verified records are self-contained and carry no external lookups, and Rosie does not retain customer content as a platform store. Where customers bring their own model credentials, the model provider's data protections apply directly; where Rosie manages them, equivalent protections are carried through by agreement. Rosie's posture aligns with UK GDPR and Canadian PIPEDA.

Integrity of verified records

Every verification record Rosie produces is tamper-evident: it is built from a hash-chained ledger and sealed with a composite hash over its canonical inputs, and it surfaces its own integrity claims for inspection. Records are self-contained β€” they resolve their own references and do not drift as the underlying system changes. The procedures that govern a verification are authored, inspectable documents, so how something was verified is always legible.

Software supply chain

Software bill of materials

Rosie maintains a CycloneDX SBOM for the components it ships, generated in its build pipeline and available for review under diligence.

Dependency-license policy enforced

The build fails on disallowed or unknown dependency licenses, so what ships stays within a permissive, auditable policy.

Code reviewed before it ships

Code is reviewed before it enters the product, regardless of how it was authored.

IP approach documented

Our approach to third-party intellectual property β€” including how we use AI-assisted development tooling β€” is documented and available for review under diligence.

Standards and credentials

Rosie participates in open identity and verification standards as a relying party: it verifies and references external credentials, and does not issue them. Where Rosie refers to third-party standards or ecosystems, it does so by plain reference, without implying endorsement.

Fair and transparent commercials

Rosie's commercial model is designed to avoid conflicts of interest: pricing follows a uniform formula rather than discretionary selection, terms are disclosed to the people they affect, and partners retain the ability to take their data with them.

Working with us on a pilot or procurement?

Detailed governance documentation β€” including our software bill of materials, third-party-IP and code-provenance policy, and data-protection terms β€” is available to partners and their legal or security advisors on request.

Messages
Send a message to start a conversation with our support team.