Skip to content

Buyer diligence

Trust is a reviewable system, not a slogan

Review Regsta data isolation, immutable evidence, compliance monitoring, GDPR workflows, subprocessors, and explicit assurance boundaries in one buyer-diligence record.

Data

Database-enforced separation

Forced Row Level Security separates companies beneath the application. Cross-tenant tests verify the boundary, and each server action rechecks authority.

Evidence basis: The release gate replays PostgreSQL policies on a non-bypass role and exercises real cross-company denial cases.

Boundary: Repository and local-runtime evidence is not an independent penetration test, ISO certificate, or SOC report.

History

Records resist silent rewriting

Time-event and audit history is append-oriented during its retention period. Corrections preserve the original and the reason for change.

Evidence basis: Database triggers, legal-state constraints, correction lineage, export finality, and destructive denial probes run in the release gate.

Boundary: External legal review and production migration evidence remain separate release controls.

Monitor

Stored compliance assessments

The configured work-time signal evaluates the company on a recurring schedule and stores dated results, while keeping employer judgement explicit.

Evidence basis: Deterministic rule tests, stored daily assessments, scheduler readiness, and inspection-folder contracts cover this behavior.

Boundary: The signal evaluates recorded data; it is never a legal verdict and cannot infer leave, illness, collective agreements, or exceptions.

Privacy

EU data handling and controlled deletion

The primary product database and authentication region are configured in the EU. Employee access, controlled anonymization, configurable retention, and audited deletion are product workflows.

Evidence basis: Product contracts cover retention, anonymization, employee access, and account deletion; privacy, DPA, and subprocessor documents are maintained for review.

Boundary: Customer-specific signature, final legal approval, processing locations, and transfer safeguards must be confirmed for the actual engagement.

Supply

Named operational providers

Supabase provides database and authentication in an EU region, Vercel operates the application, and Upstash supports rate limiting. Regsta does not sell employee data.

Evidence basis: The named providers match the configured database/authentication, application-hosting, and shared rate-limit dependencies; no advertising or employee-tracking SDK is present.

Boundary: Provider status, terms, regions, and subprocessors can change and require reconfirmation before contract or production use.

We publish only claims we can demonstrate. Request the supporting boundary or document at hej@regsta.com. Independent certification is not implied where it has not occurred.