Bounded evidence
Normalized findings exclude raw logs, raw scanner responses, secret values, prompt content, and unrestricted workflow contents.
Trust boundary
CanaryGuard collects bounded release facts and keeps deterministic policy authoritative. The public intake never requests credentials, source archives, source code, production logs, deployment configuration, contracts, quotations, invoices, or payment details.
Controls
Normalized findings exclude raw logs, raw scanner responses, secret values, prompt content, and unrestricted workflow contents.
Digest-only credentials, repository grants, explicit roles, and concealed cross-tenant resources protect customer boundaries.
Strict schemas, request-size limits, credential-shape rejection, idempotency digests, consent, and a honeypot constrain public intake.
Every lead receives a 180-day retention deadline. Operators must delete or lawfully extend it when that deadline arrives.
Written scopes, contracts, quotations, payments, and private customer materials remain outside the application.
Staged provider flags, additive migrations, explicit rollback order, and revision health checks preserve operational control.