Trust Evidence
The documents buyers should request before go-live.
Architecture, backup, AI, incident, subprocessors, and limitation notes behind a serious ERP procurement review.
Architecture
Security architecture at buyer-review level.
User access
Browser app, JWT sessions, 2FA/TOTP, RBAC, audit events
Application layer
FastAPI services, tenant-scoped dependencies, structured logs, request IDs
Data layer
PostgreSQL, tenant_id scoping, RLS evidence, Alembic migrations, backups
Integrations
Stripe, LHDN MyInvois, email, storage, AI provider, optional BI exports
Backup and restore policy
- Production database should run on managed PostgreSQL with automated backups enabled.
- Restore drills must be performed into a test database before relying on backup promises.
- Post-restore checks should include migrations, tenant isolation, login, invoice, inventory, and audit smoke tests.
- Customer-specific RPO/RTO commitments must be confirmed in the commercial agreement.
AI data handling policy
- AI features are tenant-scoped and should receive minimum necessary operational context.
- AI output is advisory by default; high-impact operational actions require human confirmation.
- Prompt and response handling must be validated against the selected AI provider before enterprise rollout.
- Customer data should not be used for provider training unless explicitly agreed in the deployment terms.
Incident response process
- Classify severity, affected tenants, user impact, data exposure risk, and integration impact.
- Contain the issue, preserve evidence, notify accountable owners, and communicate customer impact clearly.
- Track remediation, customer follow-up, and post-incident review actions.
- Run tabletop exercises for DB outage, suspected tenant leak, LHDN outage, Stripe webhook backlog, and AI provider outage.
Data retention and export
- Customer business data remains customer-owned.
- Operational exports should be available in standard formats such as CSV, Excel, PDF, or database export by agreement.
- Cancellation retention and deletion timing must be stated before subscription.
- Legal, tax, audit, and regulatory retention requirements may override generic deletion windows.
Subprocessors
The published sub-processor list.
The vendors that receive Customer Data on this deployment, with what each receives and where. The Data Processing Agreement incorporates this list; a new vendor is announced 14 days before it is switched on.
DigitalOcean LLC
Application hosting, managed PostgreSQL and object storage for uploaded files
Singapore (DigitalOcean SGP1)
Cloudflare, Inc.
Edge network in front of the API: TLS termination, DDoS protection, and the signup bot check (Turnstile)
Global (anycast)
Vercel Inc.
Hosting of the web application and twentycore.ai, and the proxy that carries the application's API requests to DigitalOcean
Global edge network
Stripe, Inc.
Subscription billing and payments
US (with EU/SG sub-processors per Stripe DPA)
Resend
Transactional email delivery
US / global sub-processors per Resend DPA
Sentry (Functional Software, Inc.)
Error monitoring and performance telemetry for the API and the web application
US (EU region available on request)
Google LLC (Gemini API)
AI text + vision generation for tenant-facing AI features
US
LHDN MyInvois (Inland Revenue Board of Malaysia)
Government e-Invoice clearance for MY tenants
MY (Malaysia, government cloud)
Reviewed 2026-09-14. Source: https://api.twentycore.ai/api/v1/legal/sub-processors
Downloadable docs
Public review notes for procurement and security teams.
These are buyer-review notes, not fake certification claims. Use them to structure diligence, then confirm final commitments in the contract.
Security architecture
Security architecture review note
A buyer-level map of access, application, data, integration, logging, and deployment controls to review before production.
Backup and restore
Backup and restore policy
Operational backup expectations, restore drill requirements, and evidence buyers should request before go-live.
AI data handling
AI data handling policy
How AI features should be scoped, reviewed, and governed when connected to tenant-specific ERP data.
Incident response
Incident response process
The severity model, containment workflow, customer communication expectations, and post-incident review path.
Subprocessors and residency
Subprocessors and data residency note
Where the sub-processor list is published, what it covers, and where Customer Data is stored.
Legal and security review
Legal and security review checklist
A buyer-ready checklist that separates operational evidence from contractual commitments before production use.
Data processing review
Data processing review note
A structured review of customer data categories, processors, retention, export, deletion, and AI/integration boundaries.
Limits
No unsupported certification claims.
TwentyCore is not SOC 2 or ISO 27001 certified today. LHDN production approval depends on customer authority setup and live credentials. Backup, rollback, monitoring, email, storage, Stripe, and AI provider evidence should be captured for each production environment.