Security & operations

Security, continuity, and operations

Review product behavior, production configuration, provider commitments, and customer agreement as one implementation record.

Reference version 1.1 · Updated September 4, 2026

Control domains

Control domains
DomainImplementation expectation
Identity and accessAuthenticated accounts, assigned roles, privileged-access controls, and verified tokens.
Tenant isolationTenant-scoped relational rows, dedicated vector namespaces or collections, and namespaced object storage.
EncryptionTLS 1.3 in transit and AES-256 at rest for applicable managed services.
Model useCustomer data processed under applicable zero-training commercial terms.
Execution isolationNetwork-disabled sandboxes for managed deep-review tasks where configured.
LifecycleDocumented residency, retention, deletion, backup, and restoration behavior.
Human governanceNamed review and release gates before approved external action.

Map the complete data path

  • Who makes the request and which resource is authorized?
  • Which application, worker, model endpoint, sandbox, and storage service handles each stage?
  • Where do source PDFs, extracted text, embeddings, page artifacts, dossiers, reports, and backups travel?
  • How do retention, deletion, recovery, and customer handoff work?

Continuity evidence

Record recovery objectives, backup coverage, restoration procedure, exercise date, observed recovery result, data-loss result, and open corrective actions. Treat targets and observed evidence as different fields.

Detail: failure and recovery behavior

Detail: failure and recovery behavior
ControlBehavior
Attempt ownershipA stale background attempt cannot replace the state written by a newer worker.
Resume by provenanceIndexed pages can be reused only when source hash, embedding model/schema, and required assets still match.
Page-level isolationOne failed page does not automatically discard successful pages from the same document.
Marked fallbackAvailable text and raw assets can remain as an explicitly stubbed page when visual analysis fails.
Retained originalThe source PDF remains available for citations, resume, and verification-packet assembly.
Report-level traceWarnings, audit entries, methodology, measurements, questions, context coverage, and sources travel with the report.

Detail: recovery objectives

RTO is the target time to restore service. RPO is the target recoverable data-loss window. These operational targets are distinct from the observed results below and from any customer-specific agreement.

Detail: recovery objectives
TierRTO targetRPO targetRecovery method
API and compute< 15 minutes0 minutesStateless multi-zone services and revision rollback
Relational database< 1 hour< 5 minutesWAL, snapshots, and point-in-time recovery
File and artifact storage< 30 minutes< 1 hourRedundant object storage and source-hash verification
Vector search store< 2 hours< 4 hoursRe-indexing from primary document metadata and source files

Recorded recovery exercise: August 4, 2026

The recorded production-mirror exercise reported 100% recovery success, zero data loss, and zero open corrective actions. The table preserves measured timings separately from recovery objectives.

Recorded recovery exercise: August 4, 2026
PathMeasured recoveryTargetRecorded outcome
Application compute3 min 45 sec< 15 minPassed
Database failover18 min 20 sec< 60 minPassed · zero records lost
Storage linkage4 min 10 sec< 30 minPassed
Vector re-ingestion42 min 15 sec< 120 minPassed
Need help applying this page to an evaluation?Ask a product question