Privacy

Production deployments should store account, entitlement, submission, material-access, and Workbench usage records in private managed services with least-privilege access.

Provider keys stay server-side. Authenticated local development uses the same paid-access and persistence boundaries as deployed environments; test-only fixtures remain isolated.

Workbench uploads require prompt-injection and data-safety review before production file support is enabled.