Trust and compliance
Potloc’s certifications, audit reports, policies and security documentation live in one place:
Start there for a security review, a questionnaire, a copy of a report, or the list of sub-processors. None of it is repeated here.
What lives where
Section titled “What lives where”This site and the trust centre answer different questions, and a fact lives on only one of them:
| Question | Where |
|---|---|
| Which certifications does Potloc hold, and against which framework? | trust.potloc.com |
| Which policies govern Potloc’s people, systems and vendors? | trust.potloc.com |
| Where is data hosted, and who are the sub-processors? | trust.potloc.com |
| How do I request a report or answer a security questionnaire? | trust.potloc.com |
| How does sign-in work, and what can my organisation enforce? | Signing in, SSO |
| What does the platform hold about me and my respondents? | Privacy and data handling |
| What is specific to reaching Potloc over MCP? | MCP security and compliance |
The rule behind the split: the trust centre says how Potloc is run and audited; this site says how the product behaves. A certification, a policy or a hosting fact is renewed on a schedule and belongs on the trust centre, so the docs site never carries a stale copy. A behaviour of the product (what a role unlocks, what an export contains, how a session ends) changes with a release and belongs here.
Asking a question the trust centre does not answer
Section titled “Asking a question the trust centre does not answer”Write to support@potloc.com. Architecture questions, a compliance requirement specific to your engagement, and anything you believe is a security issue all go to the same address.