Policy

Privacy notes

Agent Blackbox captures evidence for harnessed runs. The privacy posture is built around minimization, encrypted payload custody, redacted previews, and clear verification limits.

Run-scoped capture

Evidence collection applies to work launched inside the AgentBox harness. Capture scope should be visible to operators and limited to the run, workspace, tools, and identities configured for that execution.

Payload handling

Sensitive observable payloads should be encrypted when evidence encryption is configured. Indexing, summaries, and operational telemetry should use redacted previews and stable hashes where practical.

Customer control

Enterprise storage can use customer-controlled S3 compatible custody and customer-held decrypt authority. Hosted custody is available for managed deployments with the same separation between evidence and telemetry.