Partile Data Room¶
An evolving, audit-ready evidence repository for privacy, security, ML governance, and trust & safety. Its purpose is to demonstrate compliance continuously — so that audits, certifications (SOC 2 / ISO 27001), regulator inquiries, enterprise security reviews, and investor/M&A due diligence are answered from here rather than scrambled for. Git history is the audit trail: every change is timestamped and attributable.
Honesty rule
This pack only claims what is true. Partile is pre-beta with no real
users yet; many controls are recorded as not started or designed
because that is the correct, defensible state. A data room that
overstates is evidence against us.
Not legal advice
Items needing qualified legal/privacy counsel are marked [counsel required]. Provisional framework mappings must be confirmed by counsel before external reliance.
Control posture at a glance¶
Sixty-four controls across five families, crosswalked to SOC 2, ISO 27001:2022,
and UK GDPR in the control register. Statuses follow the
shared model not started → designed → implemented → verified → operational.
pie showData title Control status distribution (64 controls)
"implemented" : 30
"designed" : 17
"not started" : 15
"operational" : 2
Start here¶
| Section | What it answers |
|---|---|
| Diagrams | The key points, visually: architecture, data flows, control crosswalk, subprocessors, DSAR/incident handling, retention |
| Control register | The spine. One row per control: status, owner, evidence, SOC 2 / ISO 27001 / UK GDPR mapping |
| Technical pack | CTO/diligence view: architecture, data, security, infrastructure, SDLC |
| Registers | RoPA, retention schedule, subprocessors, DSAR/incident logs, accepted risks |
| Policies & Procedures | The rule layer and how it operates |
| Product | Product spec, user journeys, decision log |
| Counsel queue | The consolidated hand-off pack for legal/privacy counsel |
| How this data room works | Structure, two-tier rule, status model, upkeep cadence |
What is deliberately not here¶
Tier 2 (restricted) material is pointed to, never contained: signed DPAs, real DSAR/incident contents, entity details, secrets and credential values, raw pentest detail. See the two-tier rule and the evidence register.
Rendered 2026-07-04 21:09 UTC from the canonical data-room tree. This site is a read-only presentation layer — the markdown sources remain the single source of truth.