Trust boundary

Security and privacy

CanaryGuard collects bounded release facts and keeps deterministic policy authoritative. The public intake never requests credentials, source archives, source code, production logs, deployment configuration, contracts, quotations, invoices, or payment details.

Controls

Designed for minimum necessary access.

01

Bounded evidence

Normalized findings exclude raw logs, raw scanner responses, secret values, prompt content, and unrestricted workflow contents.

02

Tenant isolation

Digest-only credentials, repository grants, explicit roles, and concealed cross-tenant resources protect customer boundaries.

03

Safe acquisition

Strict schemas, request-size limits, credential-shape rejection, idempotency digests, consent, and a honeypot constrain public intake.

04

Retention

Every lead receives a 180-day retention deadline. Operators must delete or lawfully extend it when that deadline arrives.

05

External commerce

Written scopes, contracts, quotations, payments, and private customer materials remain outside the application.

06

Recovery

Staged provider flags, additive migrations, explicit rollback order, and revision health checks preserve operational control.