gothink software runs inside your boundary and no document ever leaves it. This page carries the SOC 2 status with a named auditor and a date, the subprocessor list, the DPA, a pre-completed security questionnaire, the data-flow diagram and the pen-test summary. Ask for any of it and it arrives as a document, not as a meeting.
Signed release bundles installed in your VPC, on-prem or air-gapped environment under your IAM and keys.
No page, no field, no metadata, no usage telemetry. The runtime has no network dependency on gothink to operate or to validate its licence.
Extraction runs on models deployed in your boundary. Where you choose to use an external model, it is your account, your contract and your decision, and it is off by default.
Licence state is a signed file with an expiry, installed alongside the runtime. Renewal is a new file, delivered like any offline release bundle.
Steward corrections retrain extractors inside your deployment. Nothing you process is used to train gothink's models or any other customer's.
Masking and entitlements are applied before anything is indexed or served, so downstream RAG and agents inherit your access rules.
A roadmap alone reads as “not yet certified”, so here is the specific commitment instead: the engagement, who is running it, when the window opens and when the report lands. This table is updated the day a status changes, not the quarter after.
| Standard | Status | Auditor & date | Scope |
|---|---|---|---|
| SOC 2 Type I | Engaged | Auditor engaged Sep 2026 · report targeted Q1 2027 | gothink corporate environment, release pipeline and support processes. Serves as the bridge document while Type II is observed |
| SOC 2 Type II | Observation window open | Window opened Sep 2026 · report targeted Q3 2027 | Same scope, observed over a 6-month period running in parallel with Type I rather than after it |
| ISO/IEC 27001 | Planned | 2028 | Information security management system |
| GDPR / UK GDPR | Applies by design | — | gothink processes no customer personal data in its own systems; the runtime processes it in yours |
| HIPAA-eligible deployment | Supported | BAA available where gothink is a processor | PHI never leaves the customer boundary; masking at the govern stage |
| Penetration test | Per major release | Summary shared on request | Runtime, control plane and release pipeline |
Type II cannot be shortened — it requires a real observation window, and any vendor claiming otherwise is describing a Type I. So both run at once: the window opened the week the auditor was engaged, and the Type I report exists to give your risk team something to read in the meantime rather than to substitute for the real one.
Ask for the compensating controls document. It sets out what is in place today, control by control, against the SOC 2 trust services criteria, and it is written to be read by your security team rather than by your procurement team. The stronger argument in the meantime is architectural: at Enterprise and Sovereign the runtime executes inside your boundary, under your IAM, on your keys — the certification covers our corporate environment, and your documents were never in it.
A completed CAIQ-style questionnaire, so your team starts from a document rather than a blank one. Offered before you ask for it.
Request the questionnaireThe standard data processing agreement and the current subprocessor list, with the note that on in-boundary deployment none of them see a page of your data.
Request the DPAWhat crosses inward, what never crosses outward, and where every credential lives. The same diagram your architects will draw on.
Architecture referenceControl by control against the SOC 2 criteria, for the period before the report is issued.
Request the controls documentPer major release, with findings and remediation status. Shared under NDA.
Request the summarySource escrow with a named agent on Enterprise and Sovereign, released on defined trigger events. Because a small vendor should expect to be asked.
Ownership and escrowOwnership claims in this market are usually made about weights that live on the vendor’s infrastructure, under a base-model licence nobody checked for transferability. Your architects will ask three questions. These are the answers, before they ask.
The base model is named in your order-form schedule rather than described as “a leading open model”. gothink warrants that its licence permits the derivative weights to be transferred to you and run without gothink. Any base model whose licence cannot support that is not eligible for the runtime — the constraint sits in our model selection, not in your contract’s small print.
Standard open weight files with the tokenizer and configuration, plus adapter weights where tuning is adapter-based, plus the records and lineage as documented schemas. No proprietary container, no format that requires Forge to read. If your team can load a model from a public repository, they can load this.
Open weights are served today by several independent inference providers as well as on your own hardware, so portability is demonstrable rather than promised. On request we will run your exported weights outside gothink’s software, in front of your engineers, before you sign. An ownership claim that has never been tested is a marketing claim.
“Nothing you run trains our models” raises a fair question: then how does the product improve? The answer is that we learn from the pipeline’s own behaviour, not from what passed through it — and the distinction is auditable rather than rhetorical.
| Category | Leaves your boundary? | What happens to it |
|---|---|---|
| Documents, pages, images | Never | Processed in place. Not transmitted, not retained by gothink, not available to gothink staff |
| Extracted values and records | Never | Written to your systems under your retention policy |
| Tuned weights and steward corrections | Never | Retrain your extractors inside your deployment. Yours permanently |
| Your eval set and its scores | Never | Used to certify your accuracy floor. Not aggregated, not benchmarked against other customers |
| Pipeline behaviour signals | Only with consent | Which field types abstain most often, which layout structures defeat a classifier, which confidence thresholds later produced corrections, which schema shapes needed amendment after a regulatory change. Counts and categories, never content |
If a clause layout defeats the classifier at one firm, the shape of that failure informs the next pack release — a new validation rule, a revised gate default, an added field definition. Every customer gets the improvement. No customer gets another customer’s documents, values or model.
Behaviour signals are off unless you switch them on, the setting is per deployment, and turning it off later changes nothing about your accuracy floor or your support. The schedule listing exactly which signals are collected is an annex to the DPA, not a paragraph in a privacy policy.
The signal payload is written to a local log before transmission, in the clear, so your security team can read exactly what would leave and block it at the network layer if they disagree. We would rather you verified this than believed it.
Because the runtime is in your boundary, the subprocessor list for customer data is empty. The list below covers gothink's own corporate operations only.
| Purpose | Subprocessor | Customer documents or fields? |
|---|---|---|
| Customer documents, fields, lineage, weights | None | Never leaves your boundary |
| Support ticketing and email | Named in the DPA pack | No — correspondence only |
| Source hosting and release signing | Named in the DPA pack | No — gothink code only |
Every release is a signed bundle with a changelog and an SBOM. Air-gapped deployments receive the same bundle by the channel agreed at onboarding.
Release notesSecurity patches for the current and previous major version. End-of-support dates are published twelve months ahead.
Support policyReport a vulnerability and we acknowledge within two business days, triage within five, and notify affected licensees with a patch or mitigation.
gothink engineers use accounts you provision and revoke, with your logging. There is no standing access after onboarding unless an operations tier requires it.
Independent testing of the runtime and control plane; summary shared with licensees under NDA.
The contracting entity, its jurisdiction of incorporation and its registration number are stated on the order form and in the DPA pack, both available on request before any commercial conversation.
It comes back completed, alongside the architecture reference and the compensating controls document. The runtime never asks you to trust a promise the topology does not already enforce.
Twenty-five documents from your own estate, labelled by your own experts. Free, no contract, and you keep the report either way.
Schema mapping, confidence gates and a ground-truth set, at a fixed price with a fixed end date. Exit at the pilot gate having paid the first milestone only.
Go live on the licence with the tuned weights handed over. Releases, packs and support carry on from there.