Private before publish
Every generated course starts as a private draft. Learners cannot retrieve lesson bodies until an authorized admin publishes the course and assigns access.
Trust center / Control ledger
No borrowed badges. No certification theatre. This page separates the controls Rampwise operates now from the standards it does not claim.
Active controls
Every generated course starts as a private draft. Learners cannot retrieve lesson bodies until an authorized admin publishes the course and assigns access.
Organization-scoped data is protected by database row-level security or server operations that verify the authenticated member and role.
Database, model-provider, and future billing credentials are read only in server runtimes and are not shipped in browser bundles.
Course generation is instructed and validated against the submitted procedure, with explicit review before operational use.
The homepage reads source text before signup, but keeps it in the current browser session until you choose to create the private draft.
Security, privacy, legal, and procurement requests enter a private server-only review ledger through the form below.
Explicit boundary
Rampwise is not presented as SOC 2, ISO 27001, HIPAA, or other regulated-data compliant at launch.
External review badges will appear only after the corresponding profile is verified and real customers have earned the published threshold.
Self-serve deletion, formal data export, configurable retention, and enterprise provider agreements are not launch features.
Evidence routes
Private intake
Use this route for responsible disclosure, privacy rights, procurement questions, or product concerns.