Tenant Data Isolation
We will not bypass the dual-client boundary in the customer API. Elevated access is restricted to authentication bootstrap only — all business data operations run on the authenticated user path.
What this means for you
Your sites, decision records, and configuration are only readable and writable by your account. No internal operation accesses your data outside the authenticated path.
Learning Auto-Apply Gate
We will not enable policy learning auto-apply by default. Rollout requires explicit criteria, regression gates, and staged evidence.
What this means for you
Decision behavior will not change automatically due to learning system updates. Changes require explicit operator criteria — your signal-handling posture stays predictable.
No Plaintext PII Logging
We will not intentionally log plaintext PII or secrets in signal-processing paths. Structured logs are redacted by design.
What this means for you
Personal data processed during GPC signal evaluation is not written to logs in plaintext. Logs capture decision outcomes, not user identifiers.