WAO logoAI Performance Intelligence Platform

Security and customer control

Keep the evaluation boundary explicit.

WAO is designed to separate customer access, provider credentials, evidence, artifacts and optional network contribution. This page describes the public operating boundary without revealing defensive implementation details.

Identity and access

Customer and platform administration use separate access boundaries. Organization and project permissions are evaluated before protected resources are returned.

Provider credentials

Approved provider credentials are configured inside a customer project, encrypted, masked in the interface and never requested through public forms.

Evidence isolation

Customer prompts, responses, artifacts, reports and evidence stay inside the authorized organization and project boundary.

Controlled artifacts

SDKs, private-engine materials and other artifacts remain approval and entitlement controlled. They are not public downloads.

Consent

Performance Network contribution is separate, off by default and requires authorized consent plus privacy thresholds.

Retention and deletion

Data handling follows the assigned service boundary. Sensitive-data requests receive additional review before an evaluation path is approved.

Audit evidence

Important administrative and customer actions are recorded with customer-safe event metadata. Public growth analytics does not collect prompts, responses or credentials.

Private endpoints

Private or custom endpoint work begins with architecture and security review. A discussion path is not an execution entitlement.

Responsible disclosure

Report a security concern privately.

Do not include credentials, tokens, private customer evidence or exploit material in a public message. Contact the WAO team through the reviewed support channel so the report can be handled securely.

Contact WAO