Trust, privacy & procurement
Review Libera before a pilot.
A single place for security, privacy, data-processing and operational documents. Statuses distinguish working product controls from templates, customer decisions, roadmap work and known remediation.
Documentation library
Security overview
Verified access, role, activity-record, demo-separation and human-review controls—plus current remediation items.
Open document →
DocumentedWorker reporting privacy notice
What the channel asks for, what it avoids, who sees each category and why perfect anonymity is not promised.
Open document →
DocumentedData processing agreement template
Controller/processor structure, processing details, assistance, deletion, audit information, transfers and annex placeholders.
Open document →
Requires customer configurationData retention & deletion policy
Current deletion behavior separated from recommended schedules that still require agreement and implementation.
Open document →
DocumentedIncident response procedure
An operational draft covering reporting, triage, containment, investigation, recovery, communication and review.
Open document →
ImplementedWorker-signal escalation protocol
The privacy-preserving path from a signal to human review, investigation, remediation and closure.
Open document →
Procurement checklist
Current status, without implied assurance.
| Review item | Status | Evidence / limitation |
|---|---|---|
| Identity-minimised worker reporting | Implemented | No name, email, phone, account or precise location is requested. |
| Aggregate-only customer signal visibility | Implemented | Customer access excludes worker free text and evidence references; grouped counts drive review. |
| Workspace roles and case permissions | Implemented | Four roles govern key supplier, case and remediation actions. |
| Activity and audit record | Implemented | Material actions are timestamped; customer users cannot update or delete audit entries through the application data API. |
| Legal and privacy templates | Documented | Drafts for pilot review; not lawyer-approved or ready for signature without completion. |
| Retention schedule | Requires customer configuration | No automated configurable retention schedule exists today. |
| Incident contact and notification window | Requires customer configuration | Set in signed documentation; no public hour-count is promised. |
| Organisation/site/supplier public-read restrictions | Remediation required | Current anonymous lookup rules are broader than production procurement should accept. |
| Worker evidence-file access controls | Remediation required | Storage access must be tightened before production evidence uploads are enabled. |
| SOC 2, ISO 27001, independent penetration test | Roadmap | None is claimed or in progress today. |
Need this mapped to your questionnaire?
Request the current documents and identify the entity, jurisdiction, hosting, retention and notification decisions your review requires.
Request procurement material