Skip to content

Partile Data Room

An evolving, audit-ready evidence repository for privacy, security, ML governance, and trust & safety. Its purpose is to demonstrate compliance continuously — so that audits, certifications (SOC 2 / ISO 27001), regulator inquiries, enterprise security reviews, and investor/M&A due diligence are answered from here rather than scrambled for. Git history is the audit trail: every change is timestamped and attributable.

Honesty rule

This pack only claims what is true. Partile is pre-beta with no real users yet; many controls are recorded as not started or designed because that is the correct, defensible state. A data room that overstates is evidence against us.

Not legal advice

Items needing qualified legal/privacy counsel are marked [counsel required]. Provisional framework mappings must be confirmed by counsel before external reliance.

Control posture at a glance

Sixty-four controls across five families, crosswalked to SOC 2, ISO 27001:2022, and UK GDPR in the control register. Statuses follow the shared model not started → designed → implemented → verified → operational.

pie showData title Control status distribution (64 controls)
  "implemented" : 30
  "designed" : 17
  "not started" : 15
  "operational" : 2

Start here

Section What it answers
Diagrams The key points, visually: architecture, data flows, control crosswalk, subprocessors, DSAR/incident handling, retention
Control register The spine. One row per control: status, owner, evidence, SOC 2 / ISO 27001 / UK GDPR mapping
Technical pack CTO/diligence view: architecture, data, security, infrastructure, SDLC
Registers RoPA, retention schedule, subprocessors, DSAR/incident logs, accepted risks
Policies & Procedures The rule layer and how it operates
Product Product spec, user journeys, decision log
Counsel queue The consolidated hand-off pack for legal/privacy counsel
How this data room works Structure, two-tier rule, status model, upkeep cadence

What is deliberately not here

Tier 2 (restricted) material is pointed to, never contained: signed DPAs, real DSAR/incident contents, entity details, secrets and credential values, raw pentest detail. See the two-tier rule and the evidence register.


Rendered 2026-07-04 21:09 UTC from the canonical data-room tree. This site is a read-only presentation layer — the markdown sources remain the single source of truth.