Assurance status
This page is deliberately unflattering where it needs to be. Anything CheckGuard cannot prove from its own code and data is marked pending, and no code path can mark an externally owned item satisfied.
Access security
Second factor required for privileged production actions
CheckGuard-ownedAvailable nowPurging evidence, releasing a legal hold, issuing production credentials and advancing production activation all require a verified second factor in the current session. Everyday case review does not.
Fail-closed access control
CheckGuard-ownedAvailable nowSigning in is not enough. Every protected screen also requires server-verified active institution membership and an authorised role.
Tenant security
Database-level tenant isolation
CheckGuard-ownedAvailable nowEach case, capture, signal and audit row belongs to one institution and is filtered in the database, not the interface.
API security
Scoped machine credentials
CheckGuard-ownedAvailable nowLeast-privilege scopes, environment-bound credentials, idempotent submission and signed webhook delivery. Production credentials are issued only through staged activation.
Environments
Sandbox and production separation
CheckGuard-ownedAvailable nowSandbox cases are flagged, excluded from production operations views, and never mixed into production metrics.
Orchestration
End-to-end control validation
CheckGuard-ownedValidated internallyAnalysis kickoff, reviewer claim and binding decisions are single conditional claims, so duplicate attempts change nothing. Covered by an automated regression suite.
Scoring
Scoring Model v2.0 frozen and regression-tested
CheckGuard-ownedValidated internallyWeights, confidence floors, severity caps and routing thresholds are fixed and asserted by tests, so a silent change fails the build.
Experimental findings excluded from the score
CheckGuard-ownedExperimentalNumeric-versus-written amount disagreement, layout findings and forensic findings are reported to reviewers and contribute zero points.
Independent penetration test
Third-party penetration test
Externally dependentExternal validation pendingNot yet independently completed. Internal readiness material is prepared.
SOC 2
SOC 2 examination
Externally dependentExternal validation pendingNot certified. A control gap map exists; no audit has been performed.
Verified sender domain
Externally dependentExternal validation pendingNotification email is recorded truthfully as disabled until a sender domain is verified by the domain owner. In-app notification is unaffected.
Reviewer validation
Reviewer agreement, AI usefulness, review-time improvement
Externally dependentNot yet measuredThese require real named reviewers working real items. Fixture results are never reported as human evidence.
Business continuity
Application-side recovery drills
CheckGuard-ownedValidated internallyApplication redeploy and control-plane recovery have been exercised.
Provider-side restore validation
Externally dependentExternal validation pendingDatabase point-in-time restore depends on the managed provider and has not been independently drilled.
CheckGuard AI is not SOC 2 certified, has not completed an independent penetration test, and claims no regulator endorsement, examiner approval or vendor partnership. Detection performance has not yet been measured against real production fraud outcomes.