Skip to content

Trust Evidence

The documents buyers should request before go-live.

Architecture, backup, AI, incident, subprocessors, and limitation notes behind a serious ERP procurement review.

Architecture

Security architecture at buyer-review level.

1

User access

Browser app, JWT sessions, 2FA/TOTP, RBAC, audit events

2

Application layer

FastAPI services, tenant-scoped dependencies, structured logs, request IDs

3

Data layer

PostgreSQL, tenant_id scoping, RLS evidence, Alembic migrations, backups

4

Integrations

Stripe, LHDN MyInvois, email, storage, AI provider, optional BI exports

Backup and restore policy

  • Production database should run on managed PostgreSQL with automated backups enabled.
  • Restore drills must be performed into a test database before relying on backup promises.
  • Post-restore checks should include migrations, tenant isolation, login, invoice, inventory, and audit smoke tests.
  • Customer-specific RPO/RTO commitments must be confirmed in the commercial agreement.

AI data handling policy

  • AI features are tenant-scoped and should receive minimum necessary operational context.
  • AI output is advisory by default; high-impact operational actions require human confirmation.
  • Prompt and response handling must be validated against the selected AI provider before enterprise rollout.
  • Customer data should not be used for provider training unless explicitly agreed in the deployment terms.

Incident response process

  • Classify severity, affected tenants, user impact, data exposure risk, and integration impact.
  • Contain the issue, preserve evidence, notify accountable owners, and communicate customer impact clearly.
  • Track remediation, customer follow-up, and post-incident review actions.
  • Run tabletop exercises for DB outage, suspected tenant leak, LHDN outage, Stripe webhook backlog, and AI provider outage.

Data retention and export

  • Customer business data remains customer-owned.
  • Operational exports should be available in standard formats such as CSV, Excel, PDF, or database export by agreement.
  • Cancellation retention and deletion timing must be stated before subscription.
  • Legal, tax, audit, and regulatory retention requirements may override generic deletion windows.

Subprocessors

The published sub-processor list.

The vendors that receive Customer Data on this deployment, with what each receives and where. The Data Processing Agreement incorporates this list; a new vendor is announced 14 days before it is switched on.

DigitalOcean LLC

Application hosting, managed PostgreSQL and object storage for uploaded files

Singapore (DigitalOcean SGP1)

Cloudflare, Inc.

Edge network in front of the API: TLS termination, DDoS protection, and the signup bot check (Turnstile)

Global (anycast)

Vercel Inc.

Hosting of the web application and twentycore.ai, and the proxy that carries the application's API requests to DigitalOcean

Global edge network

Stripe, Inc.

Subscription billing and payments

US (with EU/SG sub-processors per Stripe DPA)

Resend

Transactional email delivery

US / global sub-processors per Resend DPA

Sentry (Functional Software, Inc.)

Error monitoring and performance telemetry for the API and the web application

US (EU region available on request)

Google LLC (Gemini API)

AI text + vision generation for tenant-facing AI features

US

LHDN MyInvois (Inland Revenue Board of Malaysia)

Government e-Invoice clearance for MY tenants

MY (Malaysia, government cloud)

Reviewed 2026-09-14. Source: https://api.twentycore.ai/api/v1/legal/sub-processors

Downloadable docs

Public review notes for procurement and security teams.

These are buyer-review notes, not fake certification claims. Use them to structure diligence, then confirm final commitments in the contract.

Security architecture

Security architecture review note

A buyer-level map of access, application, data, integration, logging, and deployment controls to review before production.

Backup and restore

Backup and restore policy

Operational backup expectations, restore drill requirements, and evidence buyers should request before go-live.

AI data handling

AI data handling policy

How AI features should be scoped, reviewed, and governed when connected to tenant-specific ERP data.

Incident response

Incident response process

The severity model, containment workflow, customer communication expectations, and post-incident review path.

Subprocessors and residency

Subprocessors and data residency note

Where the sub-processor list is published, what it covers, and where Customer Data is stored.

Legal and security review

Legal and security review checklist

A buyer-ready checklist that separates operational evidence from contractual commitments before production use.

Data processing review

Data processing review note

A structured review of customer data categories, processors, retention, export, deletion, and AI/integration boundaries.

Limits

No unsupported certification claims.

TwentyCore is not SOC 2 or ISO 27001 certified today. LHDN production approval depends on customer authority setup and live credentials. Backup, rollback, monitoring, email, storage, Stripe, and AI provider evidence should be captured for each production environment.