Skip to main content

A Noetfield Systems Inc. productProgram ops · evidence, not settlement

Discuss an integration

Pilot diligence

Data processing summary

Operational summary for MSB vendor review — not a DPA. Full DPA provided at LOI.

Scope

Workflow and API layer for program intake and evidence export.

Data we process

  • Program intake: legal entity name, contact email, corridor, consent
  • RPAA checklist responses and uploaded documents (PDF/images)
  • Ops notes, status changes, TF-###### program ID identifiers
  • Partner slug metadata for branded intake (Partner Lite)

Smart Diagnose · free-text and optional advisory LLM

  • Free-text fields are scanned for prompt-injection and sensitive patterns (SIN, account numbers, full wallets, secrets) before persistence or any model handoff
  • Telegram alerts for Smart Diagnose carry metadata only (ticket, status, severity, human-review flag) — not map answers, company names, narratives, wallets, or FINTRAC references
  • External LLM providers are not enabled for Smart Diagnose until this summary, the Privacy Policy, and the counsel-reviewed DPA disclose the provider, purpose (advisory only), and retention
  • When enabled, LLM output is advisory only: it cannot decide FILE/NO-FILE, invent unselected obligations, auto-submit reports, override human gates, or silently change deterministic scores

Where data lives

  • Application database on hosted infrastructure (region per deploy — confirm in DPA)
  • Document files on application storage (encrypted volume at deploy)
  • Optional Telegram channel alerts (metadata only — not full doc content)

Subprocessors (pilot phase)

  • Cloud hosting provider (region: Canada or US per deploy — confirm in DPA)
  • Telegram (ops notifications, if enabled)
  • Email provider (optional, when SMTP configured)
  • External LLM provider — not active for Smart Diagnose until DPA names the provider

Retention & access

Retention per pilot SOW. Admin access via token; partner API scoped by X-Partner-Token. Export: CSV and HTML compliance report for your audit folder.

Security

HTTPS required in production. Readiness status is available at /api/readiness. Pilot engagements use counsel-reviewed DPA.

Incident contact

security@trustfield.ca — acknowledge within 24 business hours (update in signed DPA).

Vendor brief (PDF)

Launch one real workflow with Launch Care included

See a public sample, confirm scope if you want, then start Controlled Launch for CAD 4,900. Expand later to Connected Production or Managed Care. Your organization remains the Reporting Entity.

Questions? Request a Workflow Proof
Data processing summary · TrustField