Project isolation
Access is scoped to the people, systems and storage locations required for a specific engagement.
TrainLayer scopes controls around the actual data, people, systems and risks in each program. We document what is implemented and do not claim certifications or compliance attestations that have not been independently obtained.
TrainLayer does not currently present itself as SOC 2, ISO 27001, HIPAA or GDPR certified. Where a buyer requires a specific framework, the requirement must be assessed and contractually scoped before work begins.
Access is scoped to the people, systems and storage locations required for a specific engagement.
NDAs, project instructions and handling restrictions are established before sensitive materials are shared.
Permissions are limited by role and project need, then reviewed when responsibilities or project status change.
Project files are exchanged through agreed channels with encrypted transport and documented handoff procedures.
Retention periods and deletion expectations are defined with the client rather than assumed globally.
Suspected exposure, misuse or control failure is escalated, contained and documented under the applicable project process.
Where the data came from, how it was collected or generated, and which transformations were applied.
The legal or contractual basis for collection and the permitted training, evaluation or internal-use scope.
Screening rules for personal, confidential, regulated or otherwise restricted information.
Acceptance criteria, sampling method, reviewer calibration, known error categories and measured results.
A traceable record of releases, corrections, exclusions and schema changes.
Coverage gaps, intended use, prohibited use and material risks that buyers should understand before deployment.
Projects define what counts as personal or sensitive information, whether it is necessary, and what treatment is required. Depending on the use case, that may include minimisation, redaction, de-identification, restricted reviewer access, exclusion rules or client-approved handling instructions.
De-identification reduces risk; it is not represented as a guarantee that re-identification is impossible.
Read the rights and consent approach ↗Purpose, composition, provenance, permitted use, limitations and ownership context.
Sampling plan, acceptance results, disagreement patterns, rework and unresolved risks.
Release identifier, schema, checksums where applicable, exclusions and change history.
We will answer based on the controls and processes actually available, identify gaps clearly, and scope additional requirements before committing to delivery.
Discuss governance requirements ↗