Security and data handling

Know which system enforces each control.

See what Acta controls, what depends on customer configuration or supplier terms, and what the available evidence cannot establish.

Trace each control to the system that enforces it.

Do not assume one retention term, supplier behavior, or infrastructure control applies to every model route.

Control areaResponsible behaviorReview boundary

Data flow and capture

Request content passes through Acta to the selected supplier or customer endpoint, and response content returns through Acta.

When rollout capture is enabled, Acta may store capped request and response content for evaluation. Effective metadata-only mode prevents rollout capture.

Supplier responsibility

Upstream providers process request content under their own terms.

Route eligibility must reflect customer requirements.

Key handling

Acta keys are shown once and stored as digests.

Customers protect, revoke, and scope issued keys.

Retention variability

Retention and training terms vary by provider, route, feature, and agreement.

Do not assume zero retention.

Administrative access

Workspace roles constrain local access.

Supplier access and procedures are separate review subjects.

Incident contact

Contact Acta through your established support channel using only the account and request identifiers needed to investigate.

Never send credentials or production content in the inquiry.

Shared responsibility

Acta enforces authentication, key policy, routing, and its own records. Customers classify data and configure eligible routes.

Supplier retention, deletion, support access, training use, and infrastructure behavior remain route-specific.

Limitations

A recorded policy does not prove every supplier behavior, retention action, or deletion result.

Treat any claim without evidence for the exact route as unknown.

Ask for evidence at the right boundary.

Identify the Workload, data classes, routes, effective key policy, provider terms, owners, and unresolved limitations.

Before use
Classify data and allowed suppliers
At configuration
Restrict models and provider routes
During operation
Review route, usage, failures, and controls
When terms change
Reassess supplier eligibility

Review the data path for one live workflow.

Identify the data, suppliers, controls, owners, and unknowns before changing production.

Apply for a design partner assessment