Skip to content

Security & governance

What is enforced, what is recorded, and what is still incomplete

This page states the current posture of the platform without overstating it. Where a control is incomplete, it is labelled incomplete.

Controls

Control posture

Governance controls

Governance controls and their current implementation state.
ControlStateDetail
Tenant boundarySynthetic tenants onlyTenant identifiers are synthetic; no client tenant exists in this build
Identity separationEnforced in schemaDe-identified analytic tokens are held apart from identity crosswalks; analytic tables carry no direct identifiers
Role and purpose controlsINCOMPLETEThe review-context selector is a presentation control only. Server-enforced RBAC is not complete and must not be relied on
ApprovalsRecorded, none grantedApproval records exist in the registry; no artifact has been approved
AuditServer-side audit recordsModel runs and governance reads are recorded server-side
Kill switchesPer-product, fail closedEach analytic product executes only where its kill switch permits
Environment promotionBlockedSynthetic artifacts are permitted in local and test only; staging and production execution is refused
RefusalLegitimate outcomeA refusal carries an explicit code and is never rendered as a generic error

Safety

Hard safety boundaries

Boundaries that hold regardless of configuration

Safety boundaries enforced by the platform.
BoundaryState
ECA member alertsNever permitted
Automated denial of therapyDisabled
Autonomous member contactDisabled
Missing treated as negativeProhibited — UNKNOWN remains UNKNOWN
Real PHI or production coefficientsNot present in this environment

Server-enforced role-based access control is INCOMPLETE in this build. Access separation shown in the interface is a review presentation control and enforces no security boundary.