Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Trust Center

Data Governance

Grantee organization evidence is grantee organization property. ArtOfTheHack is built to minimize what it holds, to make retention explicit, and to make deletion verifiable.

Controls

Documented commitments

  1. Control 01

    Grantee organization data remains grantee organization property

    Ownership of evidence, decision records, and derived artifacts stays with the grantee organization.

  2. Control 02

    Data minimization

    Connectors request only the fields required by the workflow under contract.

  3. Control 03

    Retention controls

    Retention periods for evidence and decision records are configured by the grantee organization.

  4. Control 04

    Regional deployment options

    Processing and storage can be constrained to defined regions where the deployment model supports it.

  5. Control 05

    No shared-model training without explicit authorization

    Grantee organization evidence is not used to train shared models unless the grantee organization explicitly authorizes it in writing.

  6. Control 06

    Exportable decision records

    Decision objects and audit records can be exported in structured form at any time.

  7. Control 07

    Evidence provenance

    Every claim retains its source, timestamp, and reliability score.

  8. Control 08

    Deletion procedures

    Deletion requests follow a defined process covering primary storage, derived artifacts, and backups within stated windows.

  9. Control 09

    Grantee organization-controlled keys where contracted

    Key custody can remain with the grantee organization in deployment models that support it.

These are the operating commitments of the platform and the award agreement, described as designed and delivered. They are not a certification, an independent security audit, or a compliance attestation, and ArtOfTheHack does not claim any. Protections that depend on the deployment model are scoped in writing with each grantee before connection.