Data, security and AI

What we will not build

In every software evaluation there is a moment where a buyer asks whether something is on the roadmap, and the vendor says yes. It costs nothing to say. A roadmap is a list of intentions with no date on most of them, and by the time anyone could check, the conversation that produced it is two account managers ago.

The document worth reading is the other one. Not what a company intends to build, which is cheap, but what it has decided not to build, and why. That list is falsifiable the moment it breaks, and it tells you where a product’s boundaries sit before you have arranged your operations around the assumption that they sit somewhere else.

This is ours, with a reason beside each item.

Software that judges people

No productivity surveillance. Nothing here counts keystrokes, captures screenshots or scores anyone by activity. The reason is not squeamishness: activity measurement measures motion rather than work, it rewards whoever learns to produce motion, and the day a team finds out it is running changes the behaviour it claimed to observe. The advanced attendance module carries the standing version of this as its own recorded non-goal, no covert tracking of any kind, and every capture mechanism is disclosed to the employee inside the product. Attendance exception flags are visible to the person they describe rather than held as a private score about them. Timesheet entries are declarative and approval is the control, because a manager who has to approve time is accountable for the judgement in a way a tracker never is.

No scoring or ranking of people. No attrition-risk flags, no engagement scores, no sentiment analysis over what your team writes, no algorithm producing a performance rating, no forced distribution and no stack ranking. In the performance module a manager sets one overall rating on your own scale, and nothing generates it. In advanced analytics there is no predictive scoring of individuals at all, and reports run under the identity of the person reading them, so a shared report can only narrow what that person could already see and never widen it. Engagement keeps who answered and what they answered in separate tables with no key between them, and a slice below the group threshold returns a refusal rather than numbers. The reason is the one in what should never be a model’s guess: a number attached to a person is treated as a fact about them, cannot be contested by them, and cannot be explained afterwards to anybody who asks.

No AI screening of candidates. The recruitment module runs your hiring process and does no scoring, ranking or filtering of applicants. A model trained on your past hiring reproduces it at scale with the appearance of neutrality, and the candidates removed before a human looked never find out why. This is recorded as a product decision rather than a roadmap gap, the distinction the rest of this post turns on.

Money we will not touch

No movement of customer money and no payout rail. Contractor payments and payroll disbursements happen in your bank, and Capstan records that they happened with a mandatory reference. No client funds ever rest in a Capstan account, and the current design cannot violate that rule because it moves no money at all. The reason is partly regulatory, since moving money is a licensed business with its own obligations, and partly that a system of record which also holds funds has a failure mode the record alone does not have.

No statutory payroll computation. This is the sharpest boundary in the product and the one most often misread as a gap. Capstan holds no tax rate, slab, bracket or formula anywhere, so there is nothing to fall out of date and nothing to get wrong. The payroll module compiles inputs, hands a documented export to your payroll partner, and files their computed results back onto the record. Statutory computation changes continuously in every jurisdiction, and the case for leaving it with a specialist rather than approximating it is set out on the product overview.

No employer of record. Capstan does not become the legal employer of your people anywhere. That is a different business with entities, local employment liability and its own insurance, not a feature, and the contractor module names it as an explicit non-goal in its own scope statement. If you need an EOR you need an EOR, and Capstan is the system of record around it rather than a substitute for it.

No card number anywhere in the schema. There is no card field, no adjacent column and no payment form in the product. Subscription payments run through a merchant of record on their own hosted checkout. This is a property of the data model rather than a policy promise, which means it holds regardless of anyone’s intentions, and it keeps the compliance surface of a card breach out of the product entirely.

Data that will not move

No cross-region data movement. Each region is a self-contained stack with its own database, no global control plane and no cross-region key. Residency is a property of the deployment rather than a setting somebody can flip, and moving a workspace between regions is a manual, ticketed export, import, verify and erase procedure rather than a runtime path. The cost of that is real and worth stating: there is no single view spanning two regions, so a company with people in two of them runs two workspaces.

No secondary use of your data, and no training on it. Workspace data is processed on the customer’s documented instructions and for no purpose of our own. It is not inspected to improve the product, it is not sent to an outside model and it is not used to train one. The published sub-processor register names every vendor that touches anything and separates the ones actually engaged from the ones merely admitted by policy, because publishing an unused permission overstates your data footprint and omitting a used one understates it.

Which of these are permanent

Not every no on a list carries the same weight, and blurring them is its own kind of overclaim.

Four of these are structural. No card data and no cross-region runtime path are properties of the schema and the deployment. No funds resting in a Capstan account is an architectural ruling the current design cannot breach. No statutory payroll computation is permanent by mode: the absence of any rate or formula is asserted in the product rather than promised about it.

Two are maintained commitments, which is a weaker category stated honestly. That no software here evaluates your people, and that your data never trains a model, are positions that could only end by an explicit decision, published before anything ships that would falsify them. They cannot end by drift: the manifesto and the security page carry them, and the rule is that the copy changes first.

And some things on the wider product are simply unbuilt, which is a different word again. Résumé parsing is a recorded deferral rather than a refusal. Single sign-on does not exist, which is why no plan withholds it. Biometric devices, kiosk mode and geo-fencing are deferred with a stated trigger rather than promised. A contractor payout rail is documented as a possible future adapter and is not built. If you need any of those now, this is the wrong product this year, and finding that out here is cheaper for both of us than finding it out in month three.

Where this leaves you

A refusal costs the buyer something, so it is only worth publishing next to who should walk away. If you want one vendor to employ your people in eleven countries, move the money and compute the tax, Capstan is not it, and no combination of modules makes it so.

The same reasoning keeps some records outside the system rather than inside it. POSH case files are the clearest example: a system of record can prove the policy was issued and acknowledged with a date and a version, hold committee terms and their expiry, and remind you when training falls due, and it should not hold the complaint file, which is confidential to the committee and belongs in a restricted place with a documented handling process.

What you get instead is a system of record with edges you can see, whose determinations come from rules you can read, that keeps your data in one region and hands it back in a documented export whenever you ask. The product overview marks those boundaries page by page, and the guide to HR software without AI surveillance covers the buying question underneath the first half of this list. If any item here stops being true, it comes off this page before it ships, not after.

Common questions

Why publish a list of things you do not do?

Because it is the half of a roadmap that can be checked. Anyone can list features that are coming, and nothing is at stake in the claim until the date passes. A refusal is falsifiable the day it breaks, which is what makes it worth reading. It is also the fastest way for a buyer to disqualify us: someone who needs employer-of-record employment or a payout rail can stop reading in a minute rather than discovering the boundary four weeks into an evaluation.

What is the difference between a refusal and a deferral?

A deferral is something not built yet, usually with a recorded trigger describing what would cause it to be built. A refusal is a position: it is not scheduled, and building it would mean changing a published commitment first. Both are honest, and confusing them is not. Résumé parsing and single sign-on are deferrals here. Statutory payroll computation, money movement and any software that scores or ranks a person are refusals, and each has a reason attached rather than only a no.

Does Capstan run payroll?

No, and it is not a feature waiting on a release. Capstan holds no tax rate, slab, bracket or formula anywhere in the product, which is a structural absence rather than a policy. The payroll module compiles your inputs, hands a documented export to your payroll partner, and files their computed results back onto the employee record so the system of record stays complete. Statutory computation belongs to the partner who maintains it for a living, and the boundary is permanent by design rather than by timing.

That was the argument. The free core is where you check it.