Trust

Security

Last updated 20 July 2026

Definite sits next to systems of record at regulated institutions. This page describes how the service is built to limit what it can reach and to make its own behaviour auditable.

Read-only by design

The strongest control we have is the one we do not need to enforce at runtime: Definite is never granted write capability.

Data in transit and at rest

Failing closed

When a feed is missing, late, or incomplete, the affected checks return Cannot verify and the dependent filing lines are held back. The service will not infer, estimate, or substitute a figure in order to produce a clean result.

Evidence and auditability

Access control

Subprocessors and hosting

We use a small number of infrastructure and support vendors, each bound by contract to protect the data they handle. A current list is available to customers on request.

Assurance

We can share our current security posture, architecture detail, and the results of any third-party assessment under NDA. If your procurement process requires a specific questionnaire or framework, tell us and we will work through it.

Reporting a vulnerability

If you believe you have found a security issue, email mazin@usedefinite.com with enough detail to reproduce it. We will acknowledge, investigate, and keep you updated. Please do not publicly disclose until we have had a chance to fix it.

Back to definite