Two supported deployment shapes. Both are managed by IT Pro Partner below the application layer.
Runs on existing netcup RS 4000 infrastructure alongside IT Pro Partner operations. Same Wasabi S3 backup pipeline, same Caddy reverse proxy, same monitoring stack (Prometheus and Grafana). Zero new infrastructure cost. Suitable for launch through Series A.
Dedicated netcup or Hetzner instances with a dedicated S3 bucket. Full isolation from ITPP operational infrastructure. Recommended for post-Series A or enterprise white-label deployments requiring independent compliance scope.
Shared responsibility: IT Pro Partner manages everything below the application layer (OS, container runtime, networking, backups, monitoring) under both options. The VerdictTank application and its model pipeline are the product team's responsibility.
Trademark clearance, the Minimum Viable Legal framework, the controller and processor role map, the sub-processor training guard, corpus confidentiality, and incident response. Carried forward from v4.0 and updated for the nine-vendor panel.
Status: preliminary clearance only. This is not a substitute for a formal search. This assessment was performed with open-web search tools only. USPTO TESS is a JavaScript-rendered application and a static fetch returns only the search shell with no query results. Before any trademark application is filed, a live interactive TESS search or a paid clearance search through a trademark attorney is required.
| Search | Result | Assessment |
|---|---|---|
| "VerdictTank" exact, web-wide | Only hit is verdicttank.com itself | No third-party commercial use found |
| "Verdict Tank" space variant | Two incidental unrelated hits, neither a business nor a registered mark | No competing commercial use. Matches are noise. |
| Trademarkia and Justia proxy queries | No results returned | Consistent with no existing registration, but not equivalent to direct TESS |
| Domain: verdicttank.com | Live, owned, serving the product | Primary domain. Confirms operational use in commerce. |
| Domain: rfptank.com | Legacy holding, same naming convention | Defensive only. Retained against a family-of-marks argument. Not a product surface. |
MVL is the internal gate name used in the architecture documents as the precondition for onboarding white-label and enterprise customers. It is not one document. It is five interlocking instruments that must all exist and be internally consistent before the white-label provisioning gate turns green.
| Component | Purpose | Applies to | Status |
|---|---|---|---|
| Terms of Service | Governs the contractual relationship with every direct user | All tiers | Drafting required |
| Privacy Policy | GDPR and CCPA compliant notice of collection and use | All tiers | Drafting required |
| Data Processing Addendum | Article 28 GDPR processor terms | Enterprise, white-label | Hard gate on white-label |
| AI Disclaimer (DISC-001) | Non-removable versioned notice: output is AI opinion, not professional advice | Every scored surface | Engineering spec complete, legal copy needs counsel sign-off |
| Limitation of Liability | Caps aggregate liability at the lesser of $100 or fees paid in the preceding 12 months | All tiers, embedded in ToS | Drafting required |
| Governing law and venue | Recommend Delaware law with Georgia venue, pending confirmation of incorporation state | All tiers | Pending counsel |
| GDPR readiness | Lawful basis mapped per role. Articles 28, 33 and 34. SCCs or IDTA for EU transfers. | Any EU user | Framework mapped, SCC execution pending white-label launch |
| CCPA and CPRA readiness | Service-provider contract terms and a consumer rights workflow | Any California resident | DSAR workflow build pending |
The Free, Pro and Enterprise tiers require Terms of Service, Privacy Policy and the AI Disclaimer at minimum before any paid launch.
| Data flow | Role | Legal basis | Agreements required |
|---|---|---|---|
| Free tier submission and review | Controller | Contract plus legitimate interest | ToS, Privacy Policy |
| Enterprise org admin and org users | Joint controller | Performance of contract | ToS, Enterprise DPA (Art. 26 GDPR) |
| White-label tenant end-users | Processor | Tenant's instructions | DPA, SCCs or IDTA, published sub-processor list |
| Panel model API calls, all nine vendors | Controller of the vendor relationship. Each model vendor is a sub-processor. | Legitimate interest | Sub-processor training guard plus a DPA with each vendor |
| Corpus contribution (aggregate scores and structural metadata) | Controller, secondary-use basis | Opt-in consent. Cannot ride on contract or legitimate interest under the purpose limitation principle, Art. 5(1)(b). | Explicit opt-in UI, anonymization pipeline, retention separate from the review record |
Enforcement rule: a vendor without a public, contractually confirmable training opt-out is excluded from the panel roster entirely and cannot be selected as a failover target. The only acceptable path for a non-compliant provider is a customer-side, explicit, revocable opt-in. Never a silent default, and never for corpus-eligible content. Each of the nine rostered vendors is audited against this clause before it is eligible for a seat, and the audit is re-run at each roster revision.
The corpus is VerdictTank's most valuable long-term asset and its highest confidentiality exposure.
| Data type | Corpus-eligible | Rationale |
|---|---|---|
| Dimension scores and panel spread statistics | Yes, opt-in | Structural, not identifying. Core signal. |
| Structural metadata (vertical, length bucket, revision count, deltas) | Yes, opt-in | Enables content and moat analytics |
| Raw proposal text | Never | Confidential business content plus potential third-party PII |
| Explanation and audit finding text | Never in raw form | Critique text frequently quotes the submission verbatim |
| Chat refinement transcripts | Never as transcript content | Highest incidental-PII risk of any input surface |
Corpus contribution is off by default and requires explicit, separate opt-in. It is not bundled into ToS acceptance and is revocable at any time from account settings.
Structured around the six functions of NIST CSF 2.0.
| Function | VerdictTank action |
|---|---|
| Govern | Named incident commander. Breach classification criteria documented before any incident. |
| Identify | Asset inventory: transactional database, corpus database, credentials for all nine model vendors, white-label tenant segments. |
| Protect | Row-level-security multi-tenant isolation, sanitization gate, sub-processor training guard, per-vendor spend ceilings. |
| Detect | Alerting on anomalous data access, bulk export, and cross-org query attempts. Health-gate telemetry on every panel dispatch. |
| Respond | GDPR: 72-hour notification to the supervisory authority (Art. 33). CCPA: notification without unreasonable delay. |
| Recover | Post-incident review documented. White-label tenants notified per their individual DPA terms. |
Scenario: a customer submits a proposal, receives a favorable panel verdict, acts on it, and the verdict was wrong in a way that led to a bad decision. This is primarily a reputational risk. The liability cap bounds legal exposure and does nothing for reputation.