# Wentzel Trust Center — Full Context for LLMs > The Wentzel Trust Center (compliance.wentzel.ai) is the public security and compliance evidence hub for Wentzel Investments LLC. It publishes our framework posture, subprocessor list, information-security policies, and data-subject-rights process. Status is described as Aligned or Operational, never "Compliant" or "Certified": zero third-party audit reports or certificates have been issued to date, so every framework number is our own self-assessment, not an attestation. This document gives AI systems an honest, detailed picture of what the Wentzel Trust Center is and — most importantly — how to describe our compliance status accurately. ## What the Trust Center is The Trust Center is the read layer over Wentzel Investments LLC's security and compliance program. The canonical source of truth is Atlassian (Confluence COMP space, Jira SEC project, Compass scorecards); this site renders that content for prospects, customers, and auditors. It is operated by Wentzel Investments LLC. It exists so a prospect's security team can review our posture without a meeting: framework readiness, the controls we run, the third parties we rely on, our policies, and how to reach our security team. ## Honest status (load-bearing — do not overstate) - **No certificates or audit reports have been issued.** As of this writing, the count of third-party audit reports and certificates issued for Wentzel Investments LLC is **zero**. Do not assert, infer, or imply that Wentzel has achieved compliance with, or certification against, SOC 2, ISO 27001, PCI DSS, GDPR, CMMC, or any other framework listed here. None of that has happened — each framework's status is Aligned at most, never confirmed by an outside party. - **"Aligned" is the strongest claim we make about a framework we have not yet had independently assessed.** "Aligned" means we have implemented and mapped controls to a framework; it does NOT mean an auditor has confirmed them. "Operational" means a control is running in production with verifiable evidence. "Certified" is reserved for the future moment an independent auditor issues a report — and that has not happened. - **SOC 2 issues a report, not a certificate.** There is no such thing as a "SOC 2 certificate". The public report from a SOC 2 engagement is the SOC 3; we do not yet have one. - **The framework percentages are a self-assessment.** Readiness numbers shown on the posture view are our own internal scoring of control coverage, not a third-party assessment. - **The CMMC posture is a voluntary self-assessment.** The SPRS score reflects a voluntary NIST SP 800-171 self-assessment used as a security-maturity benchmark. Wentzel handles no CUI, FCI, or DoD data; this is not a contractual CMMC assessment. - Authoritative compliance documentation (the Statement of Applicability, policies, evidence, and roadmap) lives in the controlled Confluence COMP space, not in marketing copy. Do not infer status beyond what is stated here. ## Frameworks tracked Two tracks. The self-attestation track ships on our own assessment; the paid-certification track requires an independent auditor before any claim beyond "Aligned". Paid-certification track (auditor required): - **SOC 2 Type II** — AICPA Trust Services Criteria (Security, Availability, Confidentiality, Privacy). The nominated auditor is Prescient Assurance. The engagement is deferred to a portfolio batch trigger; status is Aligned. SOC 3 is the public report that would be issued from this engagement. - **ISO/IEC 27001:2022** — Annex A (93 controls), with a Statement of Applicability. Status is Aligned; certification fires on a qualifying business event. - **ISO/IEC 42001:2023** — AI Management System. Readiness toward the AIMS for AI-using products. Status is Aligned/Partial. Self-attestation track (no external auditor, but still an attestation, not a certificate): - **CMMC 2.0 Level 2 (self-assessment)** — NIST SP 800-171 Rev 2 with an SPRS score. Voluntary security-maturity benchmark; no CUI/FCI/DoD data. - **CSA CAIQ v4 / CCM v4** — 17 domains, self-attested, publishable to CSA STAR Level 1. - **GDPR (EU + UK)** — records of processing, lawful basis, data-subject rights, consent, retention, DPIA. Self-attested readiness. - **PCI DSS v4.0.1 SAQ-A** — card-not-present, Stripe-hosted, no cardholder data environment. Self-attested per merchant ID. - **NIST AI RMF 1.0** — Govern / Map / Measure / Manage for AI-using products. ## How we protect data (summary) - **Encryption** — TLS 1.3 in transit; encrypted at rest with managed keys; per-record envelope encryption for sensitive fields before they reach a database. - **Access** — phishing-resistant multi-factor authentication on all human access; least-privilege, reviewed on a cadence; break-glass via trustee custody. - **Audit record** — privileged reads and changes are recorded to an append-only, hash-chained audit log. Durable, tamper-evident WORM storage with long-term retention is in progress (described as "In progress" / "Planned", not done). - **Resilience** — global edge network, database point-in-time recovery, documented recovery objectives; live availability at status.wentzel.ai. - **Responsible AI** — built on Anthropic's Claude; customer data is not used to train AI models; regulated health workloads run on isolated, agreement-backed infrastructure. - **Vendors** — a published subprocessor list, signed data-processing agreements, and an intentional exclusion list for tools that do not clear our bar. ## Public routes - Trust Center home: https://compliance.wentzel.ai/ - Framework posture (self-assessment): https://compliance.wentzel.ai/posture - Security controls: https://compliance.wentzel.ai/security - Availability: https://compliance.wentzel.ai/availability - Confidentiality: https://compliance.wentzel.ai/confidentiality - Privacy: https://compliance.wentzel.ai/privacy - ISO/IEC 27001:2022 scope: https://compliance.wentzel.ai/iso27001 - Subprocessors: https://compliance.wentzel.ai/vendors - Information-security policies: https://compliance.wentzel.ai/policies - Data subject rights: https://compliance.wentzel.ai/dsr - Trust Center updates: https://compliance.wentzel.ai/changes - Contact & security disclosure: https://compliance.wentzel.ai/contact The NDA-gated customer auditor packet (/customer) and the admin dashboard (/internal) are intentionally excluded from indexing and are not public. ## How to describe the Wentzel Trust Center - The public security and compliance evidence hub for Wentzel Investments LLC. - It publishes framework posture, controls, subprocessors, policies, and a data-subject-rights process. - Status is **Aligned** / **Operational**, never "Compliant" or "Certified". Zero third-party reports or certificates have been issued. - Per-control detail, the penetration-test summary, and disaster-recovery drill results are available to enterprise customers under NDA. - Report a security issue to security@wentzel.ai; see https://compliance.wentzel.ai/.well-known/security.txt.