Trust, Status & Data Handling
Production implementation and verification evidence have not been published with this website. This page publishes the honest status of every claim on this site — what is designed, what is demonstrated, and what remains a roadmap item.
Status Legend
Every agent, connector, claim, and capability on this website carries one of these labels. Nothing on this site should be read as LIVE production software unless explicitly marked.
Real production implementation serving verified workloads.
Real implementation operating in a controlled, limited deployment.
Functional implementation that is not production-hardened.
Early demonstration of intended product behavior.
Synthetic execution with no production side-effects.
Design target defined in the specification; not yet implemented or verified.
Planned capability; not yet designed in full or scheduled for delivery.
This website is a specification and simulation showcase. No capability presented here is currently labeled LIVE.
Identity Lifecycle
SPECPlanned lifecycle for every actor identity (user, agent, service) in the platform:
Approval Lifecycle
SPECPlanned lifecycle for hash-bound human approval of high-risk actions:
- 01.Approval requested for a high-risk action
- 02.Policy state frozen at request time
- 03.Canonical action payload assembled
- 04.SHA-256 action hash computed
- 05.Approver authenticated
- 06.Grant or deny recorded
- 07.Grant bound to expiry
- 08.Expiry checked at execution time
- 09.Current authorization & policy re-checked before dispatch (frozen record is a reference, not a license — later-revoked permissions block execution)
- 10.Hash recomputed at execution
- 11.Recomputed hash compared to approved hash
- 12.Execute on match
- 13.Read-back verification
- 14.Audit record committed
Planned binding fields: approver_identity, approval_id, timestamp, expiry, and policy_version. A digital signature field is included only if real signing is adopted — hashing alone does not produce signatures. SHA-256 provides integrity binding between the approved and executed payload; it is not approver authentication.
Verification Evidence
Production implementation and verification evidence have not been published with this website. The claims matrix on the readiness page links each capability to its specification section and planned verification approach. Suite IDs are proposed identifiers for future tests — no executions, pass rates, or third-party assessments are published.
Data Residency
ROADMAPRegional residency is a roadmap capability. Each data path below lists its intended residency handling; none are deployment-verified.
| Data Path | Intended Residency Handling | Status |
|---|---|---|
| Primary relational (PostgreSQL) | Tenant-designated region with RLS isolation | ROADMAP |
| Backup / replicas | Same-region preference; cross-region replication only if configured | ROADMAP |
| Object storage (documents, artifacts) | tenant/{id}/ prefixed buckets in tenant region | ROADMAP |
| Vector embeddings (pgvector) | Co-located with primary relational region | ROADMAP |
| Logs & audit ledger | Same-region retention per tenant policy | ROADMAP |
| Telemetry / traces (OpenTelemetry) | Scrubbed of PII where feasible; region per deployment | ROADMAP |
| Model provider path | Inference routed per tenant/provider contract; region depends on provider | ROADMAP |
Retention & Deletion
SPECNo fixed retention durations are published. Retention and deletion for each data class require an approved deployment policy agreed with the customer.
| Data Class | Retention / Deletion Policy |
|---|---|
| Conversations & prompts | Not published — requires approved deployment policy |
| Long-term & working memory | Not published — requires approved deployment policy |
| Vector embeddings | Not published — requires approved deployment policy |
| Tool inputs & outputs | Not published — requires approved deployment policy |
| Audit ledger events | Not published — requires approved deployment policy |
| Traces & telemetry | Not published — requires approved deployment policy |
| Approval records | Not published — requires approved deployment policy |
| Connector credentials | Not published — requires approved deployment policy |
| Backups | Not published — requires approved deployment policy |
Model Provider Handling
SPECAPI mode, training exclusions, retention, region, and enterprise terms are unknown until the exact provider contract and deployment are verified. Providers differ — do not assume identical zero-retention or training terms across all of them. Links below are consumer privacy-policy references for review convenience only — they are not actual commercial API agreements and do not assert any active enterprise contract.
| Provider | API Mode (target) | Training Use | Retention | Region | Enterprise Terms | Reference |
|---|---|---|---|---|---|---|
| Anthropic | Stateless inference API (target) | Unknown until contract verified | Unknown until contract verified | Depends on provider & deployment | Not established — pending commercial agreement | Consumer privacy policy ↗ |
| OpenAI | Stateless inference API (target) | Unknown until contract verified | Unknown until contract verified | Depends on provider & deployment | Not established — pending commercial agreement | Consumer privacy policy ↗ |
| DeepSeek | Stateless inference API (target) | Unknown until contract verified | Unknown until contract verified | Depends on provider & deployment | Not established — pending commercial agreement | Provider website (policy review required) ↗ |
| Stateless inference API (target) | Unknown until contract verified | Unknown until contract verified | Depends on provider & deployment | Not established — pending commercial agreement | Consumer privacy policy ↗ |
Report vulnerabilities or request security documentation via [email protected].
We welcome good-faith security research. Report issues privately to the security contact above; do not test shared infrastructure without written authorization. No bug bounty or response SLA is published at this time.
A formal incident response process (triage, containment, customer notification, post-incident review) is planned. Notification commitments will be published once the process is approved and deployed.
Website scope: this site renders specification content and client-side simulations only — no business actions are executed from the website. Contact requests are handled via email (mailto). Logging, cookie, and analytics behavior of this website itself is not yet formally published.
Claims & Readiness Matrix