SYNTHETIC DEMONSTRATION — NOT CUSTOMER EVIDENCE

Evidence ID: EVD-001
Document date: 2026-06-20
Fictional owner: Ilya North
Scope: DocWeave AI hosted production scope

# Cinderline Security Overview

## Scope
This document describes the fictional security program for the DocWeave AI hosted production scope.

## Security ownership
The Founder & CTO holds executive accountability. The Security & Platform Lead coordinates the security program and maintains the operating procedures referenced by this pack.

## Program operation
Core procedures are reviewed annually and after material changes. A product-scoped risk review records risks, treatment owners, and review dates. The company does not claim SOC 2, ISO 27001, or equivalent certification.

## Hosted-service controls
Customer traffic and service-to-service flows carrying customer content use encrypted transport. Stored customer content and backups are encrypted at rest. Application health, service errors, selected administrative activity, and selected security signals are monitored.

## AI data boundary
Customer content is processed to provide the contracted classification and workflow service. It is not used to train a shared or general-purpose model. Review queues, confidence thresholds, and user correction are supported, subject to workflow configuration.
