Workspace separation
Application authorization and database row-level security keep each organization’s records separate.
DemarcLabs Trust Center
DemarcLabs is the support and accountability layer, not the owner of your environment. You control your records, provider choices, access, exports, and final decisions. You can leave with your operating record. Our job is to make the relationship valuable enough that you choose not to.
Security and access
Application authorization and database row-level security keep each organization’s records separate.
Documents are stored privately and require an authenticated, authorized workspace session.
DemarcLabs staff receive no standing access to customer workspaces. Support access requires an owner-approved case, stays limited to its stated purpose, expires automatically, and records every permitted correction.
Important terms and findings remain connected to their source, reviewer, approval state, and decision history.
Plain-language privacy practices and the current provider register are public. Customer-specific privacy terms, permitted data categories, and processing instructions are documented in the applicable Order Form and Data Processing Addendum.
Security you can evaluate
Workspace separation, private storage, role controls, owner-approved support access, automatic access expiration, and attributable activity history.
Defined data scope, private source documents, malware screening, evidence-linked review, restricted-data rules, governed exports, and documented deletion.
Release gates, authenticated tenant-boundary testing, security headers, rate controls, health checks, incident procedures, and application rollback.
DemarcLabs publishes only assurance and certification claims supported by current evidence. SOC 2 and ISO 27001 certifications are not currently represented.
DemarcLabs builds accessibility into public and customer workflows and publishes the measures, testing approach, and reporting process in the Accessibility statement.
DemarcLabs documents the service architecture, data flow, subprocessor scope, access model, support procedure, and customer responsibilities so your team can evaluate the relationship directly.