Straight answers

The eight questions you're going to ask anyway

Every vendor answers these the same optimistic way, which is why you've learned to discount all of them. Here they are answered straight — including the four where the answer is no.

Are you SOC 2 certified? no

No — and anyone who tells you they are should show you the report. We have a SOC 2 Type II program in progress: the controls are mapped, the technical ones are largely in place (tamper-evident signed audit log, per-customer database isolation, least-privilege RBAC, managed identities with no stored secrets), and the gaps we have are organisational rather than technical.

What that means for you: if your procurement requires a completed Type II report today, we will not pass that gate, and we would rather tell you now than six weeks into an evaluation. If you can accept a vendor mid-programme, we will walk you through the control map line by line.

Do you support SSO? partly

OIDC: yes, in production. Customers federate their own identity provider and sign in with credentials their organisation already controls. We run this ourselves on Microsoft Entra.

SAML 2.0 and SCIM 2.0: built, but never run against a live IdP. Both are implemented against the standards and covered by tests — but no customer has yet connected a real Okta or Entra tenant to them. If you need SAML, you would be our first, and we would prove it in your sandbox before you signed anything.

We would rather say that than discover it together during implementation.

Can you file our MSHA 7000-1 and 7000-2? partly

We assemble and validate them. We do not transmit them, and no system does. MSHA has no filing API — every vendor that claims "automated filing" means "we produce the form".

What we actually do: the 7000-2 quarterly employment report is a stored record that rolls forward rather than a spreadsheet you re-key each quarter; the deadline sits on the compliance calendar and escalates before it's late; and we deep-link you into the MSHA portal and capture the E-Doc number back against the record, so the filing is evidenced. Part 50 timing (the 15-minute and 10-day clocks) is enforced with escalation, not just documented.

Do you integrate with our HRIS / Workday / SAP? no

Not with a live connector, no. Today roster changes come in by CSV/XLSX import — and the code that does it says so about itself. If a page on this site ever implied otherwise, that was wrong and we've fixed it.

The import is real and it works: named-site mapping, validation, whole-workbook upload. But it is an import, not a sync, and pretending otherwise would just make our first month together unpleasant.

Can I talk to a reference customer? no

Not yet — we are pre-first-customer. You would be early, with everything that implies in both directions: no reference calls, and no queue in front of you either.

What we can do instead is show you the product with your industry's data already in it, right now, without talking to anyone — see the sandbox — and publish all 95 of our product guides so you can audit the depth yourself rather than take our word for it.

What does it cost? partly

Three tiers — Essentials, Professional, Enterprise — priced per workspace rather than per seat, so adding a frontline worker who files two near-misses a year does not cost you anything.

We are not going to put a number on this page and then negotiate away from it. Tell us your sites and headcount and you will get a real figure on the first call, not a "custom quote" runaround.

Is there a mobile app? partly

The web app is built for a phone in a glove — big targets, works one-handed, anonymous QR reporting so a worker can file a near-miss without an account or a login.

There is an offline field-capture app for genuinely disconnected work (a pit with no signal), built on MAUI, that queues captures locally and syncs when there's a bar. It is not in the app stores. If offline is load-bearing for you, say so early — it changes the shape of the rollout.

Will your AI decide whether a case is recordable? no

No, and we would not build that. The AI reads the narrative, suggests a classification, cites the specific outcome signals it relied on, and names the rule (1904.7, or 1904.8 for a contaminated sharps injury). A human makes the determination.

The evidence for autonomous LLM recordability decisions is not there, and a wrong call on a recordable is a regulatory problem with your name on it, not ours. Everything the AI produces is advisory and attributed. If the AI is unavailable — or you have run out of AI credits — intake falls back to a deterministic assistant and nothing stops working.

Still want to talk?

Twenty minutes with the person who built it. You'll get a straight answer to anything not on this page too — including the ones that cost us the deal.