Security and its limits

Access control and explicit failure states protect the workflow. Detection still has limits.

Organization boundaries

Policies, scans, audits, keys, and credits belong to an organization. Membership controls access. Owners manage membership and sensitive settings; members use the product. Organization ownership does not grant access to staff operations.

Scoped integration keys

Keys can be restricted to supported scopes and policies. Raw keys are revealed once; stored digests support authentication and revocation. Send keys in an Authorization header, never in a URL or a support message.

Content and operational failures

Real-time text is processed in memory by Guardful AI. Logs have explicit temporary retention. A remotely processed policy is authorized as an immutable version with its disclosure and exact bundle; missing authorization, coverage or a required detector is an operational failure, not permission to continue. Historical versions are never silently rerouted. Your application must enforce the returned decision.

Remote processing remains disabled until the selected installation profile and provider gates are accepted. There is no automatic cloud or local fallback. See each check’s limits before relying on its output.

Service commitments

Security certification, uptime commitments and backup guarantees require explicit service terms. Detection does not establish compliance or guarantee perfect results. Review the terms and each check’s coverage for your workflow.

Read content handling details · Report a concern