CABIER Global Assurance · Self-assurance
We apply the eight Trust Gates to ourselves
A platform that asks institutions to prove their controls should show its own. This is how CABIER's own service measures against the eight AssureCore Trust Gates, including where it falls short.
Self-assessment by CABIER, not an independent audit. Updated when a control changes.
Gate by gate
Identity
LIVE
Every account is authenticated; admin accounts require a second factor from an authenticator app.
Authorisation
LIVE
Roles are held in a separate table and checked on the server. Admin tools refuse any caller without an admin role and a completed second factor.
Policy
LIVE
Database row-level policies restrict each organisation to its own records, including its audit trail.
Data
LIVE
Private brief content is held in the database and released only after a valid link is checked on the server. It is not shipped in the public site code.
Security
LIVE
Private link tokens are random, stored only as hashes, rate-limited and revocable. Crawlers receive a placeholder.
Regulatory
LIVE
Regulatory entries carry a status, a primary source and a last-verified date. Unverified entries are labelled and hidden on private links.
Resilience
ARCHITECTURE
Formal recovery objectives and a tested restore exercise are designed but not yet evidenced.
Evidence
LIVE
Admin actions, refused calls and private link views are logged with time and outcome.
Last reviewed: 29 September 2026.
The eight Trust Gates as applied to clients.
Open AssureCore