Trust & Safety

Trust, built in — not stickered on.

Trust & Safety at iDharma isn't about the people we audit — it's the standard we hold ourselves to. An audit is only worth anything if the auditor is independent, discreet, and honest. So those aren't features we advertise; they're how we operate.

What we hold ourselves to
  • Independent of what we review
  • Confidential with your data
  • Evidence-based & honest
  • Accountable & published
In brief

Trust & Safety is how we stay worthy of the trust we sell. Our independence is what makes a report defensible; our confidentiality is what makes it safe to share your systems with us; our honesty is what makes the findings mean something. This page is the plain-English version of the commitments behind all three.

The commitments

Four things every audit stands on

None of them is optional, and each is designed in — not layered over a process that doesn't earn it.

Independent

We don't build or sell the AI we assess, and we don't sell the fixes we'd recommend. A reviewer with no stake in the outcome is what makes the report defensible to a board or a regulator.

Confidential

Your systems, data, and findings are handled in confidence and are never reused to build anything. What we learn in your audit stays with your audit.

Evidence-based & honest

Every finding traces to evidence, and we neither inflate risk to sell more nor downplay it to please. A gap we can't evidence is reported as a gap, not assumed away.

Accountable

We measure against a published methodology and say plainly what an audit is — and what it isn't. No hidden rubric, no invented credentials.

How it shows up

What the commitments mean in practice

Conflicts of interest

We don't audit systems we built, and we disclose any relationship that could color the work. If a genuine conflict exists, we decline the engagement rather than caveat it.

Your data, protected

Access is limited to what the audit needs, handled under confidentiality, and retained no longer than necessary — the specifics are in our Privacy Policy. We never reuse it to train or build products.

You own the findings

The report is yours and stays confidential to you. We don't publish your results, name you as a client, or share your findings without your written consent.

Ruled out

What a trust brand has to refuse

For an auditor, the bar is integrity, not just technical legality. These are off the table — permanently.

  • Manipulative design — dark patterns, hidden costs, or a hard-to-find way to reach a human.
  • Fabricated or inflated findings — manufacturing risk to sell a bigger tier, or softening it to win a logo.
  • Selling or reusing your data — your systems and results are never a product we resell or train on.
  • "Technically true but misleading" — a report that reads clean while burying what matters.
  • Hollow trust signals — fake badges, invented credentials, or claimed accreditations we don't hold.
  • Auditing what we're paid to fix — grading our own homework, or anyone else's we have a stake in.
Speak up

Report a concern

Two clear paths. Both are monitored, and both can be raised in confidence.

Conduct & integrity

If something about an audit, a finding, or our conduct doesn't sit right — a question of independence, accuracy, or integrity — tell us and we'll look into it.

Email conduct@idharma.us

Security vulnerabilities

Found a security issue in our site, systems, or a report? Report it responsibly and we'll work with you on it — see the disclosure policy below.

Email security@idharma.us
Responsible disclosure

Security researchers are welcome

If you find a vulnerability, tell us privately at security@idharma.us and give us reasonable time to fix it before any public disclosure. We commit to acknowledging good-faith reports promptly, keeping you updated, and engaging in good faith with researchers who follow this policy. We ask that you avoid accessing or altering others' data, and stay within the scope of testing your own account.

A fuller vulnerability-disclosure policy is being published; until then, this section governs. Nothing here is a waiver of rights or a guarantee of legal safe harbor — it's our good-faith commitment to work with researchers who act responsibly.

An audit you can actually rely on.

Independent, confidential, and evidence-based — the way a trustworthy read on your AI has to be.

This page describes the standards iDharma holds itself to and how we work as an independent auditor. It is provided for transparency and is not a contract, warranty, or guarantee. Our reports are independent assessments, not certifications or guarantees that any system is safe or compliant. To raise a conduct concern, email conduct@idharma.us; for a security issue, security@idharma.us. Nothing here is legal advice.