Current posture
Private pilotWorldModel is an early-stage product running as a private, sign-in-gated application. It is not currently SOC 2 certified, independently penetration tested, or covered by a published uptime SLA. Those are tracked readiness requirements, not implied accomplishments.
Security overview →Implemented access, isolation, integration, and verification controls.Privacy notice →What product data is collected, why it is used, and how requests are handled.Pilot terms →Acceptable use, customer responsibilities, limitations, and commercial status.
Product boundaries
- Customer workspaces begin empty and contain only repositories and evidence created by authorized members.
- Execution remains isolated from production systems and requires an approved environment manifest.
- GitHub OAuth, AI, runners, and Stripe actions remain fail-closed until the operator configures their provider credentials and bindings.
- Generated repairs require human approval; WorldModel does not merge code automatically.
- Verification reports describe tested scenarios, not universal production safety.
Questions and review
Signed-in users can open a tenant-linked case from Workspace → Support. Use the Security category for vulnerability or data-handling questions. Do not include credentials, private keys, or production secrets in a support case.