Internal sandbox only.
Allowed for synthetic data, non-sensitive demo datasets, and internal experimentation only.
The commercial surface has to make the operational truth legible. BrainCaps trust is defined by isolation tiers, operator boundaries, evidence discipline, and product decisions that can survive scrutiny.
The customer surface can scale only if tenant isolation and proof quality scale with it.
A single shared story is not enough. BrainCaps already distinguishes sandbox use, standard customer use, and more demanding regulated or sensitive patterns.
Allowed for synthetic data, non-sensitive demo datasets, and internal experimentation only.
Tenant-scoped boundaries, operator discipline, retention controls, and production-grade access assumptions become mandatory.
Dedicated isolation expectations increase when the tenant is regulated, highly sensitive, or contractually constrained.
Privacy, AI governance, operator accountability, and evidence discipline need clear ownership and repeatable execution paths.
Retention, export, deletion, RoPA, DSR, DPIA, and subprocessor discipline must exist as operating routines, not just as legal text.
Use-case qualification, capability inventory, AI Act posture, model boundaries, and review before new AI-enabled behaviors are introduced.
No invisible cross-tenant access, no silent break-glass habits, and no admin drift from the private console into the customer surface.
Health, provenance, entitlements, and trust claims should be supportable by concrete evidence packs rather than marketing-only assertions.
The commercial surface can name the operating bar, but it should not pretend the evidence already exists if the controls are not yet closed.
These define the minimum seriousness expected for access control, change discipline, incident response, and evidence-backed operations.
RoPA, DSR handling, retention, deletion, lawful basis, and subprocessor discipline must be supportable by real operating routines.
Use-case qualification, model boundaries, human accountability, and change review should exist before new AI-enabled behavior reaches sensitive tenants.
When public copy, shared shell, customer workspace, and private admin are mixed together, access boundaries get blurry. The architecture should stay understandable from the outside.
Public explanation, positioning, trust framing, and routing into the product journey.
Shared identity, organizations, billing, access, and the transversal customer shell.
Customer workspace for memory, ingestion, usage, and product-scoped configuration.
Private operator console, never mixed into the public or customer route map.