Assurance status

This page is deliberately unflattering where it needs to be. Anything CheckGuard cannot prove from its own code and data is marked pending, and no code path can mark an externally owned item satisfied.

Available nowValidated internallyExperimentalExternal validation pending

Access security

  • Second factor required for privileged production actions

    CheckGuard-ownedAvailable now

    Purging evidence, releasing a legal hold, issuing production credentials and advancing production activation all require a verified second factor in the current session. Everyday case review does not.

  • Fail-closed access control

    CheckGuard-ownedAvailable now

    Signing in is not enough. Every protected screen also requires server-verified active institution membership and an authorised role.

Tenant security

  • Database-level tenant isolation

    CheckGuard-ownedAvailable now

    Each case, capture, signal and audit row belongs to one institution and is filtered in the database, not the interface.

API security

  • Scoped machine credentials

    CheckGuard-ownedAvailable now

    Least-privilege scopes, environment-bound credentials, idempotent submission and signed webhook delivery. Production credentials are issued only through staged activation.

Environments

  • Sandbox and production separation

    CheckGuard-ownedAvailable now

    Sandbox cases are flagged, excluded from production operations views, and never mixed into production metrics.

Orchestration

  • End-to-end control validation

    CheckGuard-ownedValidated internally

    Analysis kickoff, reviewer claim and binding decisions are single conditional claims, so duplicate attempts change nothing. Covered by an automated regression suite.

Scoring

  • Scoring Model v2.0 frozen and regression-tested

    CheckGuard-ownedValidated internally

    Weights, confidence floors, severity caps and routing thresholds are fixed and asserted by tests, so a silent change fails the build.

  • Experimental findings excluded from the score

    CheckGuard-ownedExperimental

    Numeric-versus-written amount disagreement, layout findings and forensic findings are reported to reviewers and contribute zero points.

Independent penetration test

  • Third-party penetration test

    Externally dependentExternal validation pending

    Not yet independently completed. Internal readiness material is prepared.

SOC 2

  • SOC 2 examination

    Externally dependentExternal validation pending

    Not certified. A control gap map exists; no audit has been performed.

Email

  • Verified sender domain

    Externally dependentExternal validation pending

    Notification email is recorded truthfully as disabled until a sender domain is verified by the domain owner. In-app notification is unaffected.

Reviewer validation

  • Reviewer agreement, AI usefulness, review-time improvement

    Externally dependentNot yet measured

    These require real named reviewers working real items. Fixture results are never reported as human evidence.

Business continuity

  • Application-side recovery drills

    CheckGuard-ownedValidated internally

    Application redeploy and control-plane recovery have been exercised.

  • Provider-side restore validation

    Externally dependentExternal validation pending

    Database point-in-time restore depends on the managed provider and has not been independently drilled.

CheckGuard AI is not SOC 2 certified, has not completed an independent penetration test, and claims no regulator endorsement, examiner approval or vendor partnership. Detection performance has not yet been measured against real production fraud outcomes.