GridZen · Reviewed 2026-10-09

Security and evaluation boundaries

GridZen distinguishes local development, controlled pilot and broader production readiness. The source implements a bounded single-tenant pilot with account authorization, provider allowlists, rate limiting and encrypted minimized audit. This does not assert an audit certification or unrestricted production availability.

Data and credentials

Subject identifiers exist during evaluation. Development audit entries record identifier types rather than raw values or full upstream payloads. Pilot traces are account scoped and encrypted. Provider credentials belong in approved deployment configuration or a secret store, never browser storage or public examples.

Before live processing

Review account boundaries, credential scope, durable audit, retention/deletion, access logging, policy ownership, operational recovery and provider-specific terms for the intended deployment. The default public production API fails closed without a configured key; production trace retrieval is disabled. These code controls do not replace a deployment review.

Continue reading