The facts we can support today.
Trust should come from specific, checkable information. We publish a claim only when we have evidence for it.
Company identity
Origin Diligence is founder-led in the Netherlands by Niek Engbers van Keulen. Contact: hello@origindiligence.com. The legal entity and registration number are not yet published.
Verified product facts
Checks and results do not change with the plan you choose.
Evidence checked: 2026-08-14Every automatic repair is recorded with the original and changed value.
Evidence checked: 2026-08-14Public verification shows file integrity and a short technical summary, not supplier plot geometry.
Evidence checked: 2026-08-14Suppliers can respond through a collection link without creating an account.
Evidence checked: 2026-08-14During the controlled pilot, customer uploads, technical screening, evidence-pack generation, paid checkout and VAT validation are rejected by the server before processing, storage, metering or billing starts.
Evidence checked: 2026-08-14Saved buyer records require authentication and membership of the relevant workspace. Consultancy client access is checked against the assigned client scope.
Evidence checked: 2026-08-14Evidence packs record SHA-256 file hashes. Public verification confirms pack identity without exposing supplier plot geometry.
Evidence checked: 2026-08-14Data handling and operations
The public website is hosted on Netlify at origindiligence.netlify.app. The custom domain origindiligence.com is pending. Firebase project origindiligence holds accounts, Firestore (eur3) and Cloud Functions (europe-west1). Website request handling on Netlify may take place outside the EEA. HTTPS with HSTS is enabled on the live Netlify site. Account export and deletion exist. Raw uploads are scheduled for deletion after 90 days once customer files are accepted; evidence packs are kept while the workspace exists. Those periods still need legal approval. A restore test has not been recorded. Incident contact is hello@origindiligence.com. We do not publish a response-time promise or a hosting, certification or availability claim.
Procurement review status
This is the information a legal, procurement or security reviewer can assess today. Open items remain release gates. We do not ask buyers to infer an answer from a missing page.
Company identity
The responsible founder, Netherlands base and contact address are published. Legal entity and registration details are not yet published.
Access controls
Saved records require authentication and the relevant workspace or consultancy client scope. This boundary is covered by route and access-control tests.
Customer files and data lifecycle
Customer-file processing is closed during the pilot at the server boundary. Demonstrations use bundled data.
Hosting location and subprocessors
The website runs on Netlify at origindiligence.netlify.app. The custom domain origindiligence.com is pending. Firebase project origindiligence uses Firestore eur3 and Functions europe-west1. Website request handling may take place outside the EEA. Processors include Netlify, Google Firebase, OpenFreeMap, Resend and Mollie. Live screening would use Global Forest Watch. Signed processor terms still need privacy review.
Retention, export and deletion
Account export and deletion controls exist. Technical defaults delete raw uploads after 90 days and keep evidence packs while the workspace exists. Those periods still require legal approval. A production export and purge test has not been recorded.
Service continuity and incidents
Incident contact is hello@origindiligence.com. There is no response-time promise. Provider backups are relied on. A restore test has not been recorded, so this gate stays open.
Billing and VAT
Paid checkout and VAT validation are closed during the pilot. Published prices are planned prices, not an offer of live service.
Product limits
The product checks technical evidence. It does not decide legal compliance, submit statements to TRACES or replace customer legal and security review.
What the product does not do
- We do not decide whether your organisation is legally compliant.
- We do not submit due diligence statements to TRACES.
- We do not replace your legal, procurement or information-security review.
- A technical screening signal is not a legal verdict.
