GLYPHLOCK // GOVERNANCE HUB

HOW WE
DOCUMENT OUR WORK.

The Master Covenant is GlyphLock's own internal documentation standard: how we write down architecture, controls, ownership and evidence. It is not a certification, an audit standard or a compliance program, and nothing on this page has been reviewed or approved by an outside body.

Every claim cites a source

If a statement here cannot be traced to code, a record, a contract, a test result or clearly labeled internal research, it does not belong on this page.

This framework carries no authority

The Master Covenant is documentation GlyphLock wrote for itself. It grants no legal, regulatory, court or third-party standing to GlyphLock or to anyone reviewed under it.

Controls are named, not implied

Each control we describe has a stated scope, a responsible person, the evidence behind it and a review date — or it is listed as a gap instead.

Gaps stay visible

Anything untested or incomplete is written down as open remediation work. Nothing incomplete is described as validated, certified or approved.

Read this first: a GlyphLock review is work performed by GlyphLock against documentation GlyphLock wrote. It is not independent, not accredited, and not a certification, audit opinion, or statement of compliance with any law or standard. If an engagement ever involves an outside assessor, that organization will be named by us in writing.
What the review actually is

A paid documentation review. GlyphLock reads what you provide, compares it against our own written Master Covenant checklist, and hands back written findings and a list of gaps. Conclusions depend entirely on the documents and access you give us.

What we look at:

Architecture and data-flow documents you supply
Which controls exist on paper and who owns them
Security documentation and known exposure
Whether records and evidence are actually kept
AI workflow accountability, where it applies
A prioritized list of gaps to fix
What it is not: not a certification, not an accredited audit, not a legal opinion, not SOC 2, not ISO, not a penetration test, and not evidence of compliance with any law or regulation. We do not verify facts we cannot see, and we do not test systems unless that testing is separately scoped in writing.
Limitations of this review

A GlyphLock review is not a certification, accreditation, audit opinion, legal advice, or approval of any kind. It creates no regulatory standing and no enforceable rights.

Findings are opinions based only on the documents and access provided, measured against the Master Covenant — a standard GlyphLock wrote for itself — and limited to the scope agreed in writing. Results cannot be presented to regulators, auditors, insurers or customers as third-party assurance. You remain solely responsible for your own legal and compliance obligations.