Trust & Governance

Evaluated on your terms. Scoped, reviewable, and reversible.

Decidian is designed to be evaluated without forcing a system replacement. Data handling, access, retention, and governance are documented with the client before any work begins — and every conclusion is traceable to the evidence behind it.

01Data Access
02Data Handling
03Retention
04Permissions
05Auditability
06Human Review
07Client Control
08Security Review

This page is maintained by Decidian to answer common security, privacy, and governance questions. It describes practices and platform behavior, and is not an independent certification or a guarantee of any specific outcome.

Shared Responsibility

Governance is a joint effort between Decidian and the client.

Decidian is responsible for how the platform processes data within the agreed scope. The client is responsible for the data it provides, the decisions it makes with the outputs, and internal approvals. Decidian supports human decision-making; it does not remove executive accountability.

Data Access

Access is scoped, agreed, and minimized.

Decidian only receives access to the data required for the agreed pilot scope. Access boundaries are documented with the client before work begins.

01.01
Scoped to the use case

Only the systems, datasets, and documents needed for the defined decision area are in scope.

01.02
Client-approved access model

Access method — read-only exports, secure share, or a client-provisioned environment — is agreed in writing before the pilot starts.

01.03
Least-privilege by default

We request the narrowest access consistent with the pilot's success criteria and remove access when the engagement ends.

01.04
Named individuals

Access is granted to named team members, not shared accounts.

Data Handling

Handled inside the boundaries the client sets.

Data is processed within the environment and controls agreed with the client. Specific handling requirements are documented alongside the pilot's scope and access model.

02.01
Documented handling plan

Storage location, transit protection, and processing boundaries are captured in the pilot's engagement documentation.

02.02
Segregation between clients

Client data and derived work products are kept logically separated across engagements.

02.03
No use for model training by default

Client data is not used to train third-party or general-purpose models without written client consent.

02.04
Client-directed subprocessors

Any third-party services that would touch client data are disclosed and require client agreement before use.

Retention & Deletion

Retained only as long as the engagement requires.

Retention windows and deletion procedures are agreed with the client and confirmed at engagement close.

03.01
Engagement-scoped retention

Working data is retained for the duration of the pilot and any agreed post-engagement review window.

03.02
Documented deletion

At the end of the retention window, data is deleted or returned per the client's instruction and a written confirmation is provided.

03.03
Deliverables retained by the client

Reviewable decision outputs and reports remain with the client; Decidian retains only what the engagement documentation permits.

Permissions & Roles

Who can see what is defined before work begins.

Roles and permissions on both sides are agreed and reviewed with the client.

04.01
Named engagement roles

The Decidian team members with access, and their responsibilities, are named in the engagement documentation.

04.02
Client-side approval chain

The client identifies who authorizes access, reviews outputs, and signs off at engagement close.

04.03
Change control

Any expansion of scope, access, or roles requires written client approval.

Auditability

Every conclusion traces back to the evidence.

Decidian is built to produce reviewable, traceable decision intelligence — not opaque recommendations.

05.01
Evidence-linked outputs

Conclusions surface the specific documents, records, or signals that support them, along with what is missing or contradictory.

05.02
Reviewable by the client

Outputs are structured so client reviewers can inspect the basis for each recommendation.

05.03
Engagement records

Scope, access decisions, deliverables, and sign-offs are documented across the engagement lifecycle.

Human Review

Decidian supports human decision-making — it does not replace it.

Outputs are decision support. Executive accountability for the underlying decision stays with the client.

06.01
Human-in-the-loop

Every material output is designed to be reviewed by a qualified person on the client side before it informs action.

06.02
No professional advice

Outputs are not legal, tax, accounting, medical, regulatory, or investment advice. Material decisions should involve qualified professionals.

06.03
Probabilistic by nature

Confidence indicators, evidence gaps, and contradictions are surfaced so reviewers can weigh them, not hide them.

Client Control

The client controls scope, access, and exit.

Clients can adjust the boundaries of the engagement at any time; changes are documented before they take effect.

07.01
Scope changes on request

Any change to data sources, systems, or the decision area under review is confirmed with the client in writing.

07.02
Pause and exit

The client can pause or end the engagement; access is revoked and data handled per the agreed exit procedure.

07.03
Portable outputs

Deliverables are provided in formats the client can retain, review, and share internally.

Security-Review Process

Evaluated on the client's terms, not ours.

Pilots are structured so procurement, security, and governance teams can evaluate Decidian without a system replacement.

08.01
Pre-engagement review

Security, privacy, and governance requirements are documented with the client before the pilot begins.

08.02
Standard questionnaires

Decidian responds to the client's security questionnaires and vendor-review processes as part of onboarding.

08.03
Trust package on request

A written trust package — covering data handling, access, subprocessors, retention, and incident contact — is available on request under NDA.

08.04
Named security contact

A single point of contact is provided for security questions and, if needed, incident notification during the engagement.

Trust Package

Request the written trust package.

Available under NDA. Covers data handling, access model, subprocessors, retention, deletion, and the named security contact for the engagement. Suitable for procurement, security, and governance review.

A note on language
Decidian describes practices, controls, and platform behavior in precise, non-absolute terms. This page does not promise that risk is eliminated, that data cannot be exposed, or that any specific regulatory or certification outcome applies to a given engagement. Compliance, certification, and legal characterizations for a specific engagement are confirmed in the engagement documentation between Decidian and the client.

Start with one decision that matters.

A focused 15–30 day pilot, scoped and governed on your terms.