Current trust posture

Trust starts with what Refinery refuses to pass.

Refinery is designed to fail closed: uncertain data is limited or blocked, a gateway read cannot execute a repair, and no completed repair claim exists without exact source readback and durable proof.

01 · ACCESS

Purpose-bound and read-only

An approved AI use case receives only its allowed fields. A gateway request cannot call the repair executor.

02 · UNCERTAINTY

Unknown means limited or blocked

Stale, conflicted, disallowed, wrong-identity, or insufficiently proven data is never silently returned as trusted.

03 · PROOF

Readback before fixed

After an allowed repair, Refinery reads the authoritative source fresh and keeps a durable receipt of the exact result.

Claims we can make now

The boundary is part of the product.

The current scope is controlled and PostgreSQL-first. General availability, broader connector readiness, and customer outcomes remain separate proof gates.

Refinery's non-negotiable standard

  • No trusted-data claim without a current purpose-bound check
  • No repair claim without governed execution
  • No fixed claim without exact source readback
  • No proof claim without a durable receipt chain
  • No silent resolution of identity conflicts or ambiguity

Not publicly claimed today

  • Universal or fully certified connector coverage
  • A production uptime or availability SLA
  • Formal security or compliance certifications
  • Customer counts, ratings, or case-study outcomes
  • Autonomous identity merges, destructive changes, or ambiguous finance repair

Before any design-partner path

Five things must be explicit.

No customer-data engagement begins on trust alone. Its purpose, scope, access, decision policy, and evidence plan must be reviewed and documented.

Use case and source

The exact AI or workflow decision, PostgreSQL scope, data class, volume, and accountable business owner.

Access model

The minimum credentials, permissions, network path, storage, and retention needed for the agreed mode.

Connector posture

Whether the connector is read-only, setup-ready, certification-required, or proven for the bounded repair path.

Decision policy

Which cases may be decided deterministically, which require human review, and which must be blocked.

Evidence plan

What must be read back, what a receipt contains, who reviews the result, and what stops the pilot.

Security reporting: email noreply@getrefinery.nl with “Security report” in the subject. Do not include credentials or sensitive production records in the first message.

Evaluate the boundary first

Ask the hard questions before sharing access.

A fit check should expose what is proven, what remains path-specific, and what Refinery will refuse to do.

Check your use case