Trust
Posture, stated plainly.
No third-party attestation is claimed on this site. What follows is what is true today and what is not yet in place, so a CISO can read it without a call.
What is true
- This site is static. No cookies, no analytics, no tracking scripts, no client-side JavaScript. The only external request is for web fonts. inspect the source
- A brief stays in the operator’s own account. The contact form posts to a handler on this site and stores the brief in a database in the operator’s Cloudflare account. No third-party form, CRM, or mailing service receives it. posted
- Briefs ask for the signal category, not customer records. Intake is designed so that no personal data about your customers is needed to answer it. design
- Engagement data is segregated per NewCo. Each NewCo runs on its own accounts, its own domains, and its own data stores. Nothing is pooled across anchors, and an anchor’s data never lives in another NewCo’s systems. engagement default
- Humans hold the gates. In every NewCo the statutory and consent steps (authorize, sign, pay, notarize) are performed by licensed people, never by an agent. method
What is not yet in place
- No SOC 2 report. do.enterprises has not been audited under SOC 2 or any comparable framework and does not claim to have been. When a report exists this page will say so, with its date and scope.
- No penetration test report is published. None is claimed.
- No data-processing agreement is published here. One is papered per engagement, with the engagement letter.
How to read this page
Every line carries the same claim marking as the rest of the site: posted you can check it yourself, gated attested with an exhibit pending, design how an engagement is designed to run. Nothing on this page is marked higher than it is.
Questions from a CISO or a procurement team go through the contact form; mark the brief “posture question” and a person replies in writing.
Last reviewed 2026-08-21