DocumentationSecurity and data
Browse the guides
CAIRN

Pilot guide · 6 September 2026

Work with Cairn

Security and data

The access, data and recovery requirements for a controlled pilot.

Draft for the planned pilot release. These pages describe the intended customer experience. Administration and hosted-service features are not yet released; no live product URL or support service is claimed.

Each customer's records and permissions must be isolated. Named people use managed sign-in; agents use narrow, revocable machine credentials. Customer administrators receive product permissions, not Cairn's cloud or source-code access.

The pilot scope must identify approved data, processing locations, subprocessors, retention and export rights. Choosing a UK application region alone does not establish that every support, identity, email or model provider processes data only in the UK.

Cairn should collect the minimum evidence needed for the agreed assurance purpose. Do not put passwords, API tokens, complete customer files or unrestricted prompt histories into support requests.

A backup is useful only if it can be restored. The released service must state the recovery objectives demonstrated and the retention arrangements agreed with the customer.

Protecting stored records against change is different from establishing independent historic provenance. The current prototype provides internal integrity checks with a local witness. Any stronger release claim requires its own evidence.

Incident and disclosure routes will be added after they are configured, monitored and tested. Until then, this draft is not a production security statement or certification claim.

CAIRN INTEGRITYCustomer documentation draft