Skip to content

Trust, security & data boundaries

Trust should be designed into the workflow.

Access, authority, data movement, failure behavior, and human review are defined before a connected workflow receives permission to act.

Operating principles

The boundary comes before the automation.

Source systems stay authoritative

A connected workflow reads and writes only through the approved path. Moving records or changing the authoritative system requires separate scope, reconciliation, named ownership, and a fallback.

Access is narrow and provider-native

Read and write authority is limited to the systems, fields, actions, and environments required for the agreed workflow. Vendor plan, scopes, rate limits, and administrator approval are verified before use.

Consequential authority stays human

Money movement, external commitments, exceptions, sensitive approvals, and relationship decisions remain with an authorized person unless a written scope explicitly establishes a narrower rule.

Demonstrations are isolated

Public demonstrations use fictional identities and synthetic records. They are read-only, require no customer login, and cannot access or change a customer or production system.

This public website

What crosses a boundary—and why.

Do not submit passwords, credentials, regulated records, or confidential customer information through the public website or demonstration surfaces.

Website activity
Production records a small allowlisted event name, the public page path, referrer origin, time, and a first-party identifier kept in session storage for the current tab. Reloads keep it; an independently opened tab normally receives another identifier. Preview does not write these Digital Offload events.
Hosting & protection
Cloudflare serves and protects the site. Production currently loads Cloudflare Web Analytics and Cloudflare bot-detection code, which can process network, browser, performance, and security signals separately from Digital Offload’s first-party event log. Cloudflare protection may set first-party security cookies such as cf_clearance and, when applicable, __cf_bm.
Web assistant
Submitted production chat text is sent to Anthropic to generate a reply. If the newest visitor message contains a pattern that looks like an email address or U.S. phone number, Digital Offload retains the full conversation through that reply. A later message without a matching pattern does not create another snapshot merely because prior history still contains contact information.
Scheduling
Booking opens Cal.com. Information entered there is handled under Cal.com’s service and privacy terms and is used to arrange the requested conversation.
Demonstrations
The embedded Vantrelle application remains unloaded until a visitor chooses to open it. Both external demos are synthetic and operate on separate domains.

Proof boundary

What this page does not claim.

  • No public demonstration is a customer deployment, customer result, vendor partnership, or compliance certification.
  • A platform name describes a possible connection boundary, not an already-approved connection to every account or plan.
  • No AI system receives open-ended authority over a business; scope and permissions are specific to the approved workflow.
  • This public explanation does not replace the security, data-processing, retention, support, and offboarding terms agreed for an engagement.