Trust and operating boundaries

Clear control before AI touches the workflow.

Corbel states the access, data, provider, approval, change, incident, evidence, and exit boundaries before accepting responsibility. Trust is part of the operating design, not a claim added afterward.

This page describes current commitments and current limits. It does not claim a certification or generalized enterprise readiness.

Operating commitments

Minimum access. Named authority. Controlled change.

The exact controls are completed against the engagement’s systems, data, workflow risk, and customer requirements before relevant access begins.

01

Scoped access

The customer creates and controls access. Reviews use read-only permissions wherever the system supports them. Access is limited to the named systems and work.

02

Client isolation

Each customer receives separate working space and credential handling. Client records, exports, screenshots, prompts, and bespoke artifacts do not move between customers.

03

Human authority

Consequential business decisions remain with named people. The workflow states what Corbel may perform, what requires approval, and what must escalate.

04

Approved providers

Models and providers are disclosed for the engagement. Corbel reviews the applicable privacy, retention, location, and training settings before client data is processed.

05

Controlled change

A Review does not change the live system. Authorized production work uses documented approval, testing, backup or recovery, rollback, acceptance, and a change record.

06

Documented exit

Offboarding states what is returned, retained, or deleted; how access is revoked; what documentation transfers; and how completion is confirmed.

Data boundary

Client information is used to perform the signed work.

Corbel does not sell client data, use it for advertising, or use it to train a general model. The engagement documents define the approved purpose, systems, information, providers, locations, and retention schedule.

Before

Define the data path

Confirm the work, need-to-know access, included and excluded information, approved providers, processing locations, and retention terms.

During

Minimize and separate

Use only the information needed for the agreed purpose, keep customer work isolated, and prevent credentials from entering repositories, ordinary email, or working documents.

After

Transfer and close

Return agreed materials, revoke Corbel access, delete or retain information according to the signed schedule, and document the offboarding state.

Current assurance status

No borrowed credibility.

Corbel currently operates as a scoped service business, not a hosted multi-tenant customer platform. It does not currently claim SOC 2, 24/7 support, blanket regulatory compliance, or generalized enterprise readiness.

Corbel will complete or decline the requirements of a proposed scope before accepting it. A customer should not infer a control, certification, coverage level, or service target that is not written into the engagement.

Systems ReviewPoint-in-time operational review, not a penetration test, financial audit, or legal opinion
Operate coverageWorkflow-specific operating window, response targets, and escalation defined in the Operate Charter
Data processingEngagement-specific data schedule and approved provider list required before applicable processing
Insurance and procurementRequirements must be verified and satisfied before Corbel accepts a scope that depends on them
Incidents and evidence

Problems should produce records, not ambiguity.

The engagement names incident contacts, communication requirements, customer decision owners, and the evidence retained for investigation and corrective action.

Contain

Stop or limit the affected activity and protect relevant evidence.

Escalate

Notify the named contacts according to the agreed severity and communication path.

Correct

Investigate, recover, document contributing conditions, and track corrective action.

Improve

Update the workflow, control, runbook, evaluation, or operating standard when evidence supports a change.

Parallel Human boundary

Institutional learning without treating customers as research inputs.

Corbel is operated separately from Parallel Human. The relationship creates no default or implied right to move client information or client-derived patterns across that boundary.

Trust requirements can disqualify a project.

Corbel will defer or decline work when the required access, coverage, jurisdiction, data handling, assurance, staffing, or incident capability is not ready. A sale does not override the operating boundary.

Bring the workflow and its trust requirements.

Corbel will identify the access, provider, approval, data, incident, evidence, and exit controls the work requires before deciding whether to proceed.