Trust and evaluation evidence
Last reviewed: September 14, 2026. This page distinguishes implemented behavior from operational commitments that need verification.
Execution and evidence
Execution documentation describes hosted execution, local commands, and local records.
Trace capture records bounded call metadata when enabled. Coverage and capture failures limit the evidence.
Public challenge statistics exclude private, deleted, and fixture challenges. Recent activity uses creation time within a rolling seven-day UTC window.
Data and access
Challenges, episodes, traces, prompts, datasets, and demo requests have different access and storage paths. Do not assume one retention policy covers all artifacts.
API key documentation describes scopes and revocation. Provider documentation describes external credentials.
Not yet verified
- Hosting regions and encryption statements: not yet verified for publication on this page. Owner: Platform engineering and security.
- Subprocessor inventory: not yet verified for publication on this page. Owner: Platform engineering and security.
- Artifact retention and backup deletion: not yet verified for publication on this page. Owner: Privacy and business owner.
- Approved security contact: not yet verified for publication on this page. Owner: Security.
- Contractual service levels and certification evidence: not yet verified for publication on this page. Owner: Business owner.
Procurement answers
Each answer carries one of three statuses. A status changes only with the named owner's written approval. The same list feeds the pilot approval brief.
| Question | Status | Owner | Evidence |
|---|---|---|---|
| Where does the agent run and what is recorded? | Verified | Platform engineering | /docs/where-your-agent-runs |
| What call metadata is captured and what are its limits? | Verified | Platform engineering | /docs/trace-capture |
| How are API keys scoped and revoked? | Verified | Platform engineering | /docs/api-keys |
| How are customer model-provider credentials handled? | Verified | Platform engineering | /docs/integrations |
| Hosting regions and encryption statements | Not yet verified | Platform engineering and security | Pending approved provider inputs |
| Subprocessor inventory | Not yet verified | Platform engineering and security | Pending approved provider inputs |
| Artifact retention and backup deletion | Not yet verified | Privacy and business owner | Pending retention and deletion review |
| Approved security contact | Not yet verified | Security | Pending named contact |
| Contractual service levels and certification evidence | Not yet verified | Business owner | Pending contract terms; no certification is claimed |
| SAML or OIDC single sign-on | Not offered | Platform engineering | Google, GitHub, and invite links are the supported sign-in paths |
Do not use this page as evidence of certification or a contractual deletion guarantee.
Request a security and data review. Read the privacy policy and terms.