MAVERICK - Applied Intelligence for your Business · Trust

Trust at Maverick

How we handle personal information and the business data customers share with us, in plain English. These pages describe the controls built into the Maverick Console today. They are product controls, not a certification.

Last updated: 9 October 2026

At a glance

How the Console protects customer data

  • You control your dataThe customer is the controller. We act on its written instructions as processor and data architect.
  • One tenant per customerPostgres row-level security and Purpose-based access keep every customer's records apart.
  • Access that expiresEvery read happens under a Purpose. Grants need a reason, cannot be self-approved and expire.
  • An audit log nobody can editAppend-only for every role. Reads are logged by dataset, and AI calls without their prompts.
  • Real data only after approvalThe Console holds fictional demo data today. Real records are refused until a processing register is approved.
  • No data brokeringWe never sell customer data or move it between customers. We say de-identified, never anonymous.

Policies

Read the documents

What we do not claim yet. We have no SOC 2 report, ISO 27001 certificate or third-party penetration test, no uptime commitment and no backup or restore guarantee. A full restore test and an independent security review are planned. See the Security Overview.
Found a security issue? Email maverick@speedloopauto.com with the subject "Security report". Our reporting guidelines explain what to include.