Clear proof for AI-assisted vendor compliance review.
Huckster helps teams review vendor evidence, preserve source context, record human decisions, and export buyer-ready proof. This page separates verified controls from items that still require retained proof, legal review, or enterprise hardening.
Verified product controls
Authenticated workspace access with role-based admin, reviewer, and viewer permissions.
Tenant-scoped reviews, findings, users, operational evidence, exports, and audit events.
Human approval control: AI-assisted findings do not automatically approve vendors.
Source-backed findings where document text is readable, with manual-verification language when evidence is weak or unavailable.
Blocked approval behavior when unresolved high-risk blockers or required review notes remain.
Admin-only evidence deletion with audit trail events.
Operational evidence tracking for monitoring, backup/restore, incident response, storage smoke tests, access review, legal review, and security process readiness.
Live proof retained
Live Render app and API gate passed against the deployed environment.
Credential-backed six-PDF workflow regression passed against the live app.
Performance smoke proof retained for public app load, API health, authenticated sign-in, and authenticated review-list load.
Password-reset delivery and backup/restore proof are retained in Level 2 evidence artifacts.
Backend alert proof and uptime-monitor proof retained.
Security regression and hardening marker checks are part of the repository quality workflow.
Data and AI handling
Customer workspace records are scoped by tenant.
Uploaded vendor evidence is processed to create findings, source excerpts, review decisions, and exports.
Admins can delete active review evidence from the workspace; backup retention and legal-hold behavior require final policy language.
AI output is treated as reviewer assistance and should be verified against source evidence before reliance.
Boundaries and non-claims
!Huckster is AI-assisted review software, not legal, insurance, procurement, or security advice.
!A human reviewer remains responsible for approval, rejection, escalation, and accepted-risk decisions.
!SOC 2, penetration testing, contractual SLA/service-credit terms, SSO/SAML/SCIM, and counsel-approved legal terms are not claimed as complete unless separately evidenced.
!Legal/privacy review, final public claims, and broad recovery/SLA commitments require retained proof and review before broad enterprise commitments.
Security contact
Vulnerability disclosure process
Security reports are accepted through Huckster security.txt and this trust page contact path. This is a disclosure intake process for customer evaluation, not a bug bounty or final contractual SLA.
Report suspected vulnerabilities through the published security.txt contact path or to the accountable Huckster workspace owner during evaluation.
Include the affected URL, reproduction steps, observed impact, and a safe proof artifact; do not include unrelated personal data, secrets, or customer evidence.
Huckster triages reports by severity, records remediation work in release evidence, and verifies fixes before broad deployment.
Critical and high-severity reports are targeted for first review within one business day during customer evaluation; contractual response times require final support terms.
What buyers should ask for next
Recovery proof
Backup/restore proof is retained; keep provider evidence and restore-drill results current before making recovery-time commitments.
Legal review
Review privacy, terms, DPA, subprocessors, AI/data-use, retention, deletion, and public claims before contractual use.
Enterprise identity
SSO/SAML, SCIM, MFA policy, access reviews, and deprovisioning evidence should be confirmed before broad enterprise rollout.