Read-only by default
Initial integrations collect only the information required to investigate and validate an incident.
SECURITY
Agent traces can contain customer conversations, source code, internal instructions, records, personal information, credentials, and confidential tool outputs. The platform is being designed around deliberate access and human control.
DESIGN PRINCIPLES
Initial integrations collect only the information required to investigate and validate an incident.
No recommendation is merged or deployed without an authorized human decision.
Customer prompts, traces, code, and outputs are not used to train shared models without explicit permission.
Customers determine what is collected, redacted, retained, or deleted.
VPC and customer-controlled deployment options are planned for teams with strict security or regulatory requirements.
Maintain a record of the evidence, diagnosis, proposed change, validation results, approvals, and deployment outcome.
REVIEWABLE BY DESIGN
Deployment note: Private and customer-controlled deployment options are planned. Architecture, retention, redaction, and deployment requirements are reviewed individually during early access.
SECURITY REVIEW
Design-partner pilots are scoped around incident volume, integrations, and security needs.