Methodology & trust
This page explains the machinery behind the promises on the overview page: how every reported number gets its lineage, what we deliberately never do, how customer data is handled, and who reviews what. No hype - just the chain every value has to survive.
Every value in the workpaper - a component weight, a units figure, a state/material kilogram - travels the same five-stage chain. A number that has not completed the chain is visibly an estimate or a gap; it cannot silently become part of the record.
Why immutability matters: a validation request asks how a number was built at the time you reported it. A workpaper that can quietly rewrite itself cannot answer that question - a correction chain can.
This is the same boundary stated on the overview page, verbatim, because it does not change with the audience: producer status, exemptions, and submission are decisions and actions that belong to you, your reviewer, and your counsel. We record those decisions; we never make them.
No customer data enters consumer AI tools. If any model-assisted processing is used, it happens only under commercial no-training terms - or not at all, at your election, recorded in the engagement terms.
Before any customer document enters the workspace, a binding checklist applies: contracts (NDA/DPA), written customer data authorization, a named reviewer with recorded scope, an approved commercial no-training AI path (or none), an isolated workspace, MFA, least-privilege access, encryption, access and audit records, malware scanning on upload, and backup/recovery.
The reviewed workpaper, substantiation pack, source inventory (with hashes), and full version history are retained for the engagement's agreed retention period so a CAA validation request is a same-week answer - and everything is exportable to you on demand.
At the end of an engagement, data is exported to you and deleted on request under the agreed retention/deletion procedure. One honest caveat: an active retention obligation or legal hold blocks deletion until it lapses - and that block is itself recorded, not silent.
Software surfaces problems; it never decides them. Every material decision passes through a person whose role and reasoning are on the record — and we state plainly who that person is for each engagement, rather than implying a bench that has not been contracted.
| Element | How it works |
|---|---|
| Who reviews | Scan and close workpapers are reviewed against our documented internal QA checklist by the engagement lead before delivery. Where an engagement's statement of work includes qualified professional review, a named, contracted reviewer is assigned before we accept the project - the software records their qualification and scope. No qualified reviewer is presumed: self-serve workspaces run policy-sampled review and disclose exactly that. |
| Recorded decisions | Who decided, what they decided, the basis, and the date - captured for every resolution, approval, and correction, in an append-only audit log. |
| Separation of events | Internal review and your data approval are separate recorded events on every workpaper version - two signatures, two timestamps, never merged. |
| Blocking checks | A field with no source document, or with unresolved divergence between sources, cannot be approved. The remediation queue is worked to zero, every resolution attributed to a named owner; nothing is waved through. |
| Your decisions stay yours | Producer status, exemptions, and what to submit are decisions you make with your reviewer or counsel. We record the decision, its basis, and its date - we never compute it. |
What is shipped and continuously tested today, what is planned, and the language we refuse to inflate. Ask for the procurement pack to get all of it in writing.
| Control | Status |
|---|---|
| Workspace isolation with cross-tenant attack tests; named accounts; MFA; salted PBKDF2 (600k) passwords; server-side session revocation | Shipped & tested |
| SHA-256 hashing on every document; field-level provenance with structured citation fragments; malware scanning that fails closed; encryption at rest for stored objects | Shipped & tested |
| Sealed, hash-verified completed versions (tamper-evident) with an append-only audit trail enforced at the database layer | Shipped & tested |
| Deterministic human-judgment gates: no approval without a source, contradictions block, exports never advance regulatory state, no legal conclusions from software | Shipped & tested |
| Storage-level WORM retention lock (until it lands we say "tamper-evident", never "immutable") | Planned |
| E&O / cyber insurance (bound at first paid engagements, before any regulated-data work that requires it; current status stated in writing on request) | Planned |
| SOC 2 (control baseline targets OWASP ASVS L2 / NIST SSDF now; certification when buyer demand justifies it) | Planned |
Service commitments are process commitments: intake acknowledgment in one business day, critical missing-data notice in two, any frozen workpaper and its evidence packet retrievable in 24 hours. We never guarantee a regulatory outcome, agency acceptance, or supplier behavior.
The CY2025 reporting deadlines are behind us: Oregon, Colorado, and California annual supply reports, California's baseline producer report (CY2023 data), and the MN/MD/WA interim reports were due May 31, 2026, and California's individual source-reduction plan date (August 1, 2026) has also passed. What is live now is what follows a filing: CAA currently expects California early-fee invoices in August 2026, based on CY2025 supply data; validation, Adjustment, and Correction windows are open on filed reports (Reporting Policy V2, §§3.10–3.12); and the next annual cycle is building. Fee payments began July 1, 2025 in Oregon and January 2026 in Colorado. Dates per the Circular Action Alliance producer resource center (circularactionalliance.org), retrieved 2026-08-15 - regulatory state drifts, so verify against the official source before relying on any date here.
No. You submit in the portal; we prepare the portal-entry workpaper and record your receipt/status as evidence. We never claim remediation cures noncompliance - we make the remediation defensible.
You, with your reviewer or counsel. We record the decision, its basis, and its date - we never compute it. The same goes for any question that determines whether and what you must report.
No. Any fee figures in our workpapers are labeled illustrative planning math. Invoicing happens through CAA under approved rate schedules - we do not quote, compute, or optimize fees.
We go deep on Oregon, Colorado, and California, and track MN/MD/WA/ME deadlines only. If your obligations sit mostly outside that footprint, we will say so on the first call - a large purchase would be irrational, and we'll tell you that for free.
Not silently. Completed workpaper versions are sealed and tamper-evident; corrections create linked versions with recorded reasons. Estimates are flagged as estimates, then replaced with actuals through a recorded correction - so every kilogram stays traceable to units × component weight and its source document.
No customer data enters consumer AI tools. Model-assisted processing happens only under commercial no-training terms - or not at all, at your election.
Nothing leaves your browser. The 2-minute EPR Status & Exposure Scanner runs entirely client-side - nothing is uploaded, nothing to install, and closing the tab discards everything, including any packaging BOM you paste.
Exposure views and any fee-adjacent figures are illustrative planning math, never a quote. Verify every date and obligation against the official state and CAA sources before relying on it.