What we do with your policies and traces
This page describes what is implemented today and what is planned. We do not claim SOC 2, HIPAA, or GDPR certification, and we will not imply one before it exists.
Traces and policies are sensitive by default
A production trace can contain customer conversations, account identifiers, and internal rules. It is handled as confidential material, not as sample data.
Evidence is versioned and attributable
Every result carries a source version, run ID, artifact hash, timestamp, and reviewer where a person was involved. A result you cannot attribute is not evidence.
Blocked inputs stay blocked
If a tool response or schema is missing, the run is marked blocked. Nothing is fabricated to produce a cleaner-looking result.
Controls are scoped with each pilot
Retention windows, deployment location, access, and deletion are agreed in writing before a pilot starts, based on the sensitivity of what you send.
In place today, and what comes next
| Control | Status | Detail |
|---|---|---|
| Evidence attribution Source version, run ID, artifact hash, and timestamp on every recorded result. | In place | Source version, run ID, artifact hash, and timestamp on every recorded result. |
| Explicit blocked states Missing evidence surfaces as a blocked or inconclusive outcome rather than a substituted value. | In place | Missing evidence surfaces as a blocked or inconclusive outcome rather than a substituted value. |
| No hidden reasoning capture The product works from policies, tool calls, outputs, and traces. Private model chain-of-thought is not collected or displayed. | In place | The product works from policies, tool calls, outputs, and traces. Private model chain-of-thought is not collected or displayed. |
| Per-pilot retention agreement Retention and deletion terms are set before any customer data is accepted. | In place | Retention and deletion terms are set before any customer data is accepted. |
| Trace redaction tooling Field-level redaction on ingest, so identifiers can be stripped before storage. | Planned | Field-level redaction on ingest, so identifiers can be stripped before storage. |
| Customer-managed encryption keys Bring-your-own key for stored traces and evidence records. | Planned | Bring-your-own key for stored traces and evidence records. |
| Private deployment Deployment inside your own boundary, scoped during enterprise review. | Planned | Deployment inside your own boundary, scoped during enterprise review. |
| Third-party audit An independent review will be pursued as the platform matures. | Planned | An independent review will be pursued as the platform matures. |
What we will not say
We hold no SOC 2, HIPAA, or GDPR certification today, and nothing on this site should be read as one.
Results are verified within the declared contract and environment. That is a bounded statement, deliberately.
We do not inspect or store private model chain-of-thought, and the interface never displays it.
Need the full data-handling detail before you send anything? We will walk your security reviewer through it as part of pilot scoping.
Request a pilot