Version and owner
Effective 2026-06-25. Owner: legal-compliance. Security evidence must stay aligned with launch readiness, provider governance, and production runbooks.
- Security controls are reviewed before launch and before a client Agent handles live work.
- Operator access, provider access, and model access must stay server-side and least-privilege.
- Production readiness requires dated evidence, not public copy alone.