Data use

Public input, private evidence, and model calls stay separate.

Mindburn's public site is a source-backed evaluation surface. Real company evidence belongs behind reviewed access and explicit authority boundaries.

Disclosure map

Data-use boundaries are narrow by design.

The public site explains the boundary. It does not become a place to submit private evidence or approve company work.

Public site input

Visitor input is not company evidence.

Public forms and the public assistant are for routing and source-backed questions. Visitors should not send secrets, credentials, customer records, regulated documents, or private evidence.

Assistant requests

Assistant answers are bounded by public sources.

The public assistant can answer from indexed Mindburn routes and should return unavailable instead of inventing facts or approving work.

Evidence retention

Private evidence belongs in reviewed-access workflows.

Receipts, EvidencePacks, and ProofGraph details for real company workflows are not public site artifacts unless explicitly published and source-backed.

Code indexing

Repository evidence stays bounded by source controls.

Code Intelligence Graph indexing must respect .gitignore, deny sensitive paths, skip secret-looking files, enforce project-root containment, and treat code comments and README text as untrusted evidence unless promoted through review.

Code proof

Code graph output is evidence, not instruction.

CodeIndexReceipt, CodeImpact, affected tests, and route impact can support engineering review. They cannot approve actions, execute shell commands, mutate source files, or override HELM AI Kernel authority.

Model providers

Model-provider boundaries must be explicit.

When a workflow uses a model provider, the implementation must name what is sent, what is retained, and which authority boundary applies before side effects run.

Training

Public site copy does not grant training rights.

Mindburn does not ask visitors to submit private data for public-site evaluation and does not present public assistant input as product training data.

Public proof

Public proof stays separate from private rooms.

The llms files, research routes, and receipt demos are public proof surfaces. Private customer evidence is not implied by public wording.