KONFYDENCE / CoMaSy

SECURITY & PRIVACY

Enterprise review should start before the pilot, not after it.

This page documents what is visible in the current CoMaSy implementation and the data-governance questions that must be agreed for a pilot. It is not a certification, DPA or substitute for your organisation’s legal/security review.

CURRENT IMPLEMENTATION

Technical safeguards already present in the application.

Application security

The current web application configures security headers including CSP, HSTS, X-Content-Type-Options, Referrer-Policy and frame restrictions.

Pilot form protection

Pilot requests are validated server-side and rate-limited before lead records are created.

Consent-aware analytics

GA4 instrumentation is optional and is designed to respect explicit analytics consent before behavioural analytics events are sent.

Data minimisation

Pilot scope should define which participant and cohort data are actually required before the exercise begins. Individual-level reporting is not treated as a default requirement.

PILOT DATA

Agree the minimum data set before launch.

CoMaSy is designed around observable scenario decisions. The pilot should establish exactly which fields are required, who may access results and whether reporting is individual, cohort-level or both.

Pilot request dataName, work email, organisation, role, organisation size, objective, current platform, notes, consent and attribution fields may be collected through the pilot request flow.
Participant dataScenario responses and derived training signals may be required for a pilot. The exact participant identifiers and reporting granularity should be agreed before the exercise.
Access & retentionCustomer-specific access, retention and deletion requirements should be documented in the pilot scope or commercial agreement before live participant data is processed.

ARCHITECTURE & SERVICE PROVIDERS

What the current codebase uses.

The current Konfydence application is built on Next.js/React with Prisma and PostgreSQL/Supabase architecture and is deployed through Vercel. The pilot workflow includes a Resend email integration when configured. Consumer checkout uses Shopify.

Procurement note

Deployment-specific subprocessors, regions, retention, data-processing terms and customer security requirements must be confirmed for the actual pilot environment. This page intentionally does not claim a certification or contractual control that has not been verified.

PILOT REVIEW CHECKLIST

Questions to close before participant data is used.

REQUEST A PILOT

Bring your security and privacy questions into the pilot scope.

A qualified pilot request should make the data model and review requirements explicit before scale.

Request a Pilot →