Security, privacy & governance

Trust requires evidence, not badges.

TrainLayer scopes controls around the actual data, people, systems and risks in each program. We document what is implemented and do not claim certifications or compliance attestations that have not been independently obtained.

Current assurance position

Transparent about what exists today.

No blanket certification claims

TrainLayer does not currently present itself as SOC 2, ISO 27001, HIPAA or GDPR certified. Where a buyer requires a specific framework, the requirement must be assessed and contractually scoped before work begins.

Operational safeguards

Controls matched to project risk.

01

Project isolation

Access is scoped to the people, systems and storage locations required for a specific engagement.

02

Confidentiality

NDAs, project instructions and handling restrictions are established before sensitive materials are shared.

03

Least-privilege access

Permissions are limited by role and project need, then reviewed when responsibilities or project status change.

04

Controlled transfer

Project files are exchanged through agreed channels with encrypted transport and documented handoff procedures.

05

Retention and deletion

Retention periods and deletion expectations are defined with the client rather than assumed globally.

06

Incident escalation

Suspected exposure, misuse or control failure is escalated, contained and documented under the applicable project process.

Data governance

Every dataset should answer six questions.

View the documentation standard
01Provenance record

Where the data came from, how it was collected or generated, and which transformations were applied.

02Rights and consent

The legal or contractual basis for collection and the permitted training, evaluation or internal-use scope.

03Sensitive-data review

Screening rules for personal, confidential, regulated or otherwise restricted information.

04Quality evidence

Acceptance criteria, sampling method, reviewer calibration, known error categories and measured results.

05Version history

A traceable record of releases, corrections, exclusions and schema changes.

06Known limitations

Coverage gaps, intended use, prohibited use and material risks that buyers should understand before deployment.

Personal and sensitive data

PII is reviewed before it becomes training data.

Projects define what counts as personal or sensitive information, whether it is necessary, and what treatment is required. Depending on the use case, that may include minimisation, redaction, de-identification, restricted reviewer access, exclusion rules or client-approved handling instructions.

De-identification reduces risk; it is not represented as a guarantee that re-identification is impossible.

Read the rights and consent approach
Delivery evidence

What accompanies a governed dataset.

01

Dataset card

Purpose, composition, provenance, permitted use, limitations and ownership context.

02

Quality report

Sampling plan, acceptance results, disagreement patterns, rework and unresolved risks.

03

Version manifest

Release identifier, schema, checksums where applicable, exclusions and change history.

Enterprise review

Bring your security questionnaire.

We will answer based on the controls and processes actually available, identify gaps clearly, and scope additional requirements before committing to delivery.

Discuss governance requirements