Trust & deployment readiness
The controls present in the local prototype, the gaps still open and the conditions for customer deployment.
The hosted website previews the interface. The portable workbench is local and single-user. This page records the security boundary; it does not represent a new security audit or certification.
| Area | Present in the local prototype | Required before hosted customer use |
|---|---|---|
| Identity & data | Session token and loopback host checks; one user | Managed identity, server-side permissions and tested customer isolation |
| Secrets & connections | Server environment keys; no browser key field | Secret rotation, redacted logs and permitted connection/egress boundaries |
| External actions | Separate approval for a reviewed webhook payload | Scoped credentials, destination controls and confirmed delivery semantics |
| Tools & add-ons | No dynamic MCP/plugin marketplace | Version/source inventory, permission review and update controls |
| Costs | Model-call limit; this is not a currency spend cap | Measured usage and enforceable project spend limits |
| Operations | Local task and stage records | Access-controlled monitoring, recovery, deletion and incident response |
A staged path to customer use
Demonstration
Use synthetic or permitted public examples while testing the workflow.
Scoped pilot
Agree the data scope, expert review, acceptance criteria and deployment controls before using customer records.
Hosted product
Verify identity, isolation, secret handling, tool permissions, cost enforcement and recovery before opening a multi-customer service.
Project labels are not security boundaries. A model instruction does not enforce access control. No broker execution, device control, multi-tenant service or compliance certification is claimed.
Read the implementation boundaries