CABIER Global Assurance · Self-assurance

    We apply the eight Trust Gates to ourselves

    A platform that asks institutions to prove their controls should show its own. This is how CABIER's own service measures against the eight AssureCore Trust Gates, including where it falls short.

    Self-assessment by CABIER, not an independent audit. Updated when a control changes.

    Gate by gate

    Identity

    LIVE

    Every account is authenticated; admin accounts require a second factor from an authenticator app.

    Authorisation

    LIVE

    Roles are held in a separate table and checked on the server. Admin tools refuse any caller without an admin role and a completed second factor.

    Policy

    LIVE

    Database row-level policies restrict each organisation to its own records, including its audit trail.

    Data

    LIVE

    Private brief content is held in the database and released only after a valid link is checked on the server. It is not shipped in the public site code.

    Security

    LIVE

    Private link tokens are random, stored only as hashes, rate-limited and revocable. Crawlers receive a placeholder.

    Regulatory

    LIVE

    Regulatory entries carry a status, a primary source and a last-verified date. Unverified entries are labelled and hidden on private links.

    Resilience

    ARCHITECTURE

    Formal recovery objectives and a tested restore exercise are designed but not yet evidenced.

    Evidence

    LIVE

    Admin actions, refused calls and private link views are logged with time and outcome.

    Last reviewed: 29 September 2026.

    The eight Trust Gates as applied to clients.

    Open AssureCore