Trust and security

What we do with your data, and who decides what is true.

This page exists for the people who have to sign off on Mosaica: ICT, security, procurement, privacy and risk. It covers data handling, security posture, editorial governance and the correction pathway — and it tells you plainly which documentation we can supply on request.

Your content

Four commitments on data.

Your content stays yours

Messages, documents and assets you submit for scanning remain your property. We process them to produce your findings. We do not sell them, publish them or share them with other customers.

We do not train public models on your data

Your content is not used to train publicly available models. Where frontier models perform scanning, they are used under commercial terms that exclude your content from training.

Proprietary lenses stay exclusive

A lens built from your own audience evidence is available only to you. It is not folded into standard lenses or made available to anyone else, including competitors in your sector.

Deletion on request

You can request deletion of submitted content and the findings derived from it. Where a retained record is needed for your own audit trail, that is your decision to make, not ours.

For ICT, security and procurement

Documentation available on request.

We would rather tell you what exists than imply more than we have. Ask and we will send what applies to your assessment, or tell you honestly where something is not yet in place.

Security overview

Architecture, hosting arrangements and data-residency position, encryption in transit and at rest, access control and authentication model, logging and monitoring.

Data-handling and privacy schedule

What we collect, why, where it is stored, how long it is retained, who can access it internally, and the sub-processors involved in delivering the service.

Sub-processor list

The third parties involved in providing the service, what each one does, and the terms under which customer content is handled.

Access, roles and user management

How organisational accounts, user groups and permissions work, including how access is provisioned and removed.

Incident and breach response

How we detect, escalate, notify and remediate, and what we commit to in a customer notification.

Assessment responses

We will complete your standard security questionnaire or assessment template rather than asking you to accept ours.

Editorial governance

Who decides what the corpus says.

Entries are written by named researchers. Authorship is on the page. There is a person accountable for every claim in the knowledge base.

Entries are reviewed with the communities they describe, alongside subject-matter experts. Reviewer objections change the text before publication rather than being noted alongside it.

Criteria are community-led; weights are expert-led. The evidence comes from the communities and researchers. How heavily each factor counts in a scan is a methodological judgement we own and will explain.

Confidence is published. Findings carry a rating. Where literature is strong they are rated high; where it is thinner or contested they are rated moderate and say so.

Red lines are rules, not judgements. A small set of things must never pass, and they are held as explicit rules rather than left to a model to infer.

The governing rule

Mechanisms, never traits.

Mosaica does not produce claims about what an ethnic, national or religious group believes. It identifies documented mechanisms that shape how a message is read, names them, cites them, and rates confidence.

This is enforced editorially rather than left to output filtering, and it is the reason findings can be defended rather than merely delivered.

Findings are flags, not advice. Clearance checks wording against communications-conduct expectations and your own policies. That is a prompt for your legal, compliance or clinical review — it is not legal, regulatory or clinical advice, and it does not replace the professional who signs off.

When we are wrong

The correction pathway.

A knowledge base that cannot be corrected is a liability. Entries are versioned, and anyone — a customer, a reviewer, a member of a described community — can challenge something they believe is wrong.

Challenges go to the researchers responsible for the entry and, where the issue concerns how a community is described, to reviewers from that community. If the challenge holds, the entry is amended, the version history records the change, and lenses built on it are updated.

Scans carry the version they ran against, so a finding produced last quarter can be traced to exactly the evidence that existed at the time. That matters when a decision made months ago has to be explained.

To raise a correction, contact us with the entry and the basis for the challenge. We would rather be corrected quickly than defend something we got wrong.

Need something specific for an assessment?

Tell us which questionnaire or review you are working through and we will respond to it directly.