Trust Center

Trust, Status & Data Handling

Production implementation and verification evidence have not been published with this website. This page publishes the honest status of every claim on this site — what is designed, what is demonstrated, and what remains a roadmap item.

Status Legend

Every agent, connector, claim, and capability on this website carries one of these labels. Nothing on this site should be read as LIVE production software unless explicitly marked.

LIVE

Real production implementation serving verified workloads.

PRIVATE BETA

Real implementation operating in a controlled, limited deployment.

PROTOTYPE

Functional implementation that is not production-hardened.

PREVIEW

Early demonstration of intended product behavior.

SIMULATION

Synthetic execution with no production side-effects.

SPEC

Design target defined in the specification; not yet implemented or verified.

ROADMAP

Planned capability; not yet designed in full or scheduled for delivery.

Current Reality

This website is a specification and simulation showcase. No capability presented here is currently labeled LIVE.

Identity Lifecycle

SPEC

Planned lifecycle for every actor identity (user, agent, service) in the platform:

Create→Bind→Scope→Use→Rotate→Suspend→Revoke→Archive

Approval Lifecycle

SPEC

Planned lifecycle for hash-bound human approval of high-risk actions:

  1. 01.Approval requested for a high-risk action
  2. 02.Policy state frozen at request time
  3. 03.Canonical action payload assembled
  4. 04.SHA-256 action hash computed
  5. 05.Approver authenticated
  6. 06.Grant or deny recorded
  7. 07.Grant bound to expiry
  8. 08.Expiry checked at execution time
  9. 09.Current authorization & policy re-checked before dispatch (frozen record is a reference, not a license — later-revoked permissions block execution)
  10. 10.Hash recomputed at execution
  11. 11.Recomputed hash compared to approved hash
  12. 12.Execute on match
  13. 13.Read-back verification
  14. 14.Audit record committed

Planned binding fields: approver_identity, approval_id, timestamp, expiry, and policy_version. A digital signature field is included only if real signing is adopted — hashing alone does not produce signatures. SHA-256 provides integrity binding between the approved and executed payload; it is not approver authentication.

Verification Evidence

Production implementation and verification evidence have not been published with this website. The claims matrix on the readiness page links each capability to its specification section and planned verification approach. Suite IDs are proposed identifiers for future tests — no executions, pass rates, or third-party assessments are published.

Data Residency

ROADMAP

Regional residency is a roadmap capability. Each data path below lists its intended residency handling; none are deployment-verified.

Data PathIntended Residency HandlingStatus
Primary relational (PostgreSQL)Tenant-designated region with RLS isolationROADMAP
Backup / replicasSame-region preference; cross-region replication only if configuredROADMAP
Object storage (documents, artifacts)tenant/{id}/ prefixed buckets in tenant regionROADMAP
Vector embeddings (pgvector)Co-located with primary relational regionROADMAP
Logs & audit ledgerSame-region retention per tenant policyROADMAP
Telemetry / traces (OpenTelemetry)Scrubbed of PII where feasible; region per deploymentROADMAP
Model provider pathInference routed per tenant/provider contract; region depends on providerROADMAP

Retention & Deletion

SPEC

No fixed retention durations are published. Retention and deletion for each data class require an approved deployment policy agreed with the customer.

Data ClassRetention / Deletion Policy
Conversations & promptsNot published — requires approved deployment policy
Long-term & working memoryNot published — requires approved deployment policy
Vector embeddingsNot published — requires approved deployment policy
Tool inputs & outputsNot published — requires approved deployment policy
Audit ledger eventsNot published — requires approved deployment policy
Traces & telemetryNot published — requires approved deployment policy
Approval recordsNot published — requires approved deployment policy
Connector credentialsNot published — requires approved deployment policy
BackupsNot published — requires approved deployment policy

Model Provider Handling

SPEC

API mode, training exclusions, retention, region, and enterprise terms are unknown until the exact provider contract and deployment are verified. Providers differ — do not assume identical zero-retention or training terms across all of them. Links below are consumer privacy-policy references for review convenience only — they are not actual commercial API agreements and do not assert any active enterprise contract.

ProviderAPI Mode (target)Training UseRetentionRegionEnterprise TermsReference
AnthropicStateless inference API (target)Unknown until contract verifiedUnknown until contract verifiedDepends on provider & deploymentNot established — pending commercial agreementConsumer privacy policy ↗
OpenAIStateless inference API (target)Unknown until contract verifiedUnknown until contract verifiedDepends on provider & deploymentNot established — pending commercial agreementConsumer privacy policy ↗
DeepSeekStateless inference API (target)Unknown until contract verifiedUnknown until contract verifiedDepends on provider & deploymentNot established — pending commercial agreementProvider website (policy review required) ↗
GoogleStateless inference API (target)Unknown until contract verifiedUnknown until contract verifiedDepends on provider & deploymentNot established — pending commercial agreementConsumer privacy policy ↗
Security Contact

Report vulnerabilities or request security documentation via [email protected].

Responsible Disclosure

We welcome good-faith security research. Report issues privately to the security contact above; do not test shared infrastructure without written authorization. No bug bounty or response SLA is published at this time.

Incident Response ROADMAP

A formal incident response process (triage, containment, customer notification, post-incident review) is planned. Notification commitments will be published once the process is approved and deployed.

Website scope: this site renders specification content and client-side simulations only — no business actions are executed from the website. Contact requests are handled via email (mailto). Logging, cookie, and analytics behavior of this website itself is not yet formally published.

Claims & Readiness Matrix