Trust
What is in place today, and what is not yet.
A byline on every claim, not just the page.
This page, briefed
Trust page · September 11, 2026
The standard Byline applies to a brief, applied to what it says about itself: each statement, its status, and the section that sets it out.
- Confirmed
Byline runs demonstration programs built from public sources and has no client engagements, so nothing it publishes reports client results.
01 · Where Byline is today
- Confirmed
Evidence review, decision approval and delivery are separate records, and whoever wrote or last edited an item cannot give its Decision Approval: the database refuses it, not just the app.
02 · What Byline enforces today
- Confirmed
Every table holding program data carries the owning organization’s identifier, and Postgres row-level security is enabled and forced on all of them.
02 · What Byline enforces today
- Confirmed
The model cannot send, publish, approve or alter records.
04 · How Byline uses AI
- Not in place yet
Byline has no formal certifications such as SOC 2, no third-party penetration testing and no service-level agreements.
05 · What is not in place yet
Coverage note This summary restates the Trust page and adds no claim of its own. The page describes the product as it is built today, not results with clients.
01 · Where Byline is today
A product in development.
Byline runs demonstration programs built from public sources and has no client engagements, so nothing it publishes reports client results.
Your first brief is complimentary, on one issue you choose. Byline first checks that it can cover the issue well, and when a brief could be ready. A request never starts recurring delivery; continued service is a paid program, agreed before it starts. Request my first brief.
Byline is founder-led, and you work directly with the person who built it. About Byline.
02 · What Byline enforces today
What each control means, and how it works.
The database keeps your data apart from other organizations’.
Every table holding program data carries the owning organization’s identifier. Postgres row-level security, which checks every row against who is asking, is enabled and forced on all of them, so isolation does not depend on application code remembering to check. An automated cross-tenant test suite runs on every change to the main branch, against a hosted database built from the repository’s migrations. Production is built only from a release the suite has passed, and a release cannot be promoted while the hosted database lacks any migration it carries.
See what was reviewed and what still needs approval.
Every brief shows its evidence-review status. An Evidence Attestation records a completed review of the cited evidence and coverage. If a brief is delivered without that attestation, it says so clearly. Decisions requiring your approval are shown separately.
They are three separate records. A Byline reviewer gives the attestation, and the brief shows their name when one is recorded: each factual sentence is supported by the evidence cited, and the coverage note (what was and was not read) matches what collection did. It does not attest to the recommendation, or that every relevant development was found. Items that recommend preparing or responding, and any item marked disputed because its sources conflict, wait for your approver’s Decision Approval, which Byline cannot give on a client program: the database refuses it, not just the app. If your approver has not acted by the program’s deadline, the item goes out marked as awaiting approval or is held back, as configured. Delivery is recorded on its own, recipient by recipient. Briefs are made under a published version of your Constitution (your written priorities); since September 6, 2026, a version cannot be published until a named Byline reviewer signs it.
No one can approve their own work.
Whoever authored or last edited an item cannot give its Decision Approval. The database refuses it, not just the app.
Approvals and corrections cannot be rewritten.
Audit entries are append-only: application roles can add them but not edit or delete them. Each records who acted, what changed and when.
Access is by invitation, limited by role.
Public sign-up is disabled at the authentication provider, so accounts exist only when an administrator creates them. Viewers see only the one program they are invited to, and sign-in is rate-limited.
03 · What a client program stores
Source details, short excerpts, claims and decisions.
A program stores details about its sources, short excerpts within each source’s permitted length, the claims extracted from them, and the decisions and briefs built from those claims.
Every source must have a permission profile: who owns it, how it was acquired, what use is permitted, whether full text may be stored, and the excerpt limit. Ingestion refuses to run for a source without one.
The full text of an article is not stored unless its source’s profile explicitly permits it.
Your organization’s data can be exported, and deleted on request. Both are built into the product today.
04 · How Byline uses AI
AI extracts and drafts. Fixed rules rank and recommend.
Byline uses Anthropic’s Claude models, through Anthropic’s API, for two narrow tasks: extracting claims from source text, and drafting readable prose. When a story has more than one document, the model drafts under a stated rule: it describes the story as it now stands, so a later publication supersedes an earlier claim it contradicts, and a notice of intent never outranks the record of what was done. That rule governs the drafting, not the record: the earlier document stays in the evidence, and the item’s certainty and recommendation do not change because of it. If two sources cannot be reconciled, the item is marked disputed and needs your approver’s Decision Approval.
Prioritization, certainty labels and recommendations come from deterministic rules, not from the model.
The model cannot send, publish, approve or alter records. In the “what changed” text, any sentence it writes that does not match the source claims is removed before saving. Headlines and “why it matters” are the model’s wording, checked for naming the right subject.
Anthropic states that it does not use data sent through its API to train its models by default. Byline relies on that policy and has not opted in to anything beyond it. Anthropic’s commercial terms are the authoritative statement.
05 · What is not in place yet
Not claimed until it exists.
Byline has no formal certifications (such as SOC 2), third-party penetration testing or service-level agreements yet.
They are planned for when client engagements begin.
06 · Raising a concern
Where to send it.
Send questions, concerns or security reports through the request form: describe the concern in the issue field, and give an email address for the reply.
We would rather hear about a doubt early than discover it late.
Questions
Common questions.
01Is my organization’s data kept separate from other clients’ data?
Yes. The database enforces it, rather than relying on application code to remember. Every table holding program data carries the owning organization’s identifier, and Postgres row-level security is enabled and forced on all of them. An automated cross-tenant test suite runs on every change to the main branch, and production is built only from a release that has passed it.
02Who approves what Byline delivers?
Two different things, shown separately. Every brief shows whether a named Byline reviewer has attested to its cited evidence and coverage, and says clearly when there is no attestation. Your own approver decides any item that recommends preparing or responding, or is disputed, and that approval is shown on the item. Neither can give the other’s.
03How does Byline use AI models?
For two narrow tasks only: extracting claims from source text and drafting readable prose. Prioritization, certainty labels and recommendations come from deterministic rules, not the model. Sentences in the “what changed” text that do not match their source are removed before saving.
04What certifications or guarantees does Byline have today?
None yet: no formal certifications such as SOC 2, no third-party penetration testing and no service-level agreements. They are planned for when client engagements begin, and Byline will claim them only once they exist.