PRE-LAUNCH LEGAL PACKAGE · REVIEW REQUIRED
Security overview
The product security commitments that need implementation evidence before release.
Preview boundary
This page describes the intended security baseline, not a certification or a claim that production controls are already operating. The prototype has no live customer account, payment or company-data workflow.
Required production controls
Before launch, the service requires identity and access controls, tenant isolation, encrypted transport, secure secret handling, backup and restore testing, vulnerability management, audit logging, incident response and supplier due diligence proportionate to the data processed.
AI-specific controls
The live architecture must define approved model providers, data-retention settings, prompt-injection defenses, output boundaries, abuse reporting and a review process for high-impact workflows.
Reporting
A working security contact, incident route and final operating-entity details must be published before production access begins.