Trust is structural, not marketed.
Capital Refinery's trust posture is composed of seven primitives — data handling, tenant isolation, evidence retention, model boundaries, public verification URLs, security posture, and refusal discipline. This page is a routing hub; each section links to the surface where the underlying primitive is documented in detail. Trust claims that can't survive an independent reviewer's check don't belong here.
Seven primitives, seven surfaces
Each section below is a one-line description plus a link to the detailed surface. This hub does not duplicate content from the underlying pages — the goal is routing, not consolidation. If you’re evaluating Capital Refinery’s trust posture for an enterprise engagement, the underlying surfaces are where the depth lives.
- Primitive 01Data handling
How ingested operator data is processed, stored, and accessed. Document-ingestion pipeline, source-of-truth discipline, retention rules.
Read the data handling detail → - Primitive 02Tenant isolation
Multi-tenant architecture with strict per-tenant data isolation. Enterprise customers receive isolation guarantees consistent with institutional security requirements.
Read the enterprise security detail → - Primitive 03Evidence retention
Provenance entries, candidate IDs, and source references retained per-cell against every promoted KPI. Evidence outlives any single engine run; reproducibility is structural.
Read the data handling detail → - Primitive 04Model boundaries
Deterministic-first architecture: regex and structural extractors do the work; a small local LLM only adjudicates between candidates the deterministic layer already produced. No hallucinated KPIs because the model never invents one.
Read the model boundary detail → - Primitive 05Public verification URLs
Every Verified Financial Artifact resolves at a token-authenticated public URL — /p/<token> for IC memos, /p/ira/<token> for IRAs. The receiving counterparty verifies independently; no login required.
See the Verified Financial Artifacts category → - Primitive 06Security posture
Authentication, authorization, audit logging, and operational security across the platform. Enterprise customers receive deeper security review under NDA.
Read the security detail → - Primitive 07Refusal discipline
The engine refuses to grade what it cannot observe. Sentiment, narrative coherence, management communication style are marked not_observable rather than imputed. The refusal is enforced in engine code, identical across every reader's artifact.
Read the refusal-discipline framing →
What this page is not
This is not a compliance certification page. Capital Refinery does not currently market SOC 2, ISO 27001, or similar third-party certifications on this surface. Enterprise customers requiring those receive the relevant detail under NDA during institutional engagement. The trust posture documented here is the structural baseline; certifications layer on top.
This is also not a substitute for the receiving counterparty doing their own verification. The architecture is designed so that every artifact (IRA, IC memo, covenant forecast, board export) carries its own deterministic fingerprint and public verification URL. The trust claim is verifiable; the verification is the reader’s right, not the platform’s assertion.
Enterprise trust review under NDA.
For institutional engagements, Capital Refinery delivers detailed trust documentation, security review, and tenant isolation guarantees under NDA. Start by running a diagnostic on a real position; the trust review follows as part of institutional onboarding.