Narrow authorized intake
Only dealer-authorized source fields and purposes belong in the operational path.
Security posture
The public posture distinguishes product boundaries from runtime facts. A design commitment can define what must be true; only current evidence can show how a deployed control behaves.
Governing boundaries
These boundaries define the intended product posture. They do not substitute for deployment-specific assurance.
Only dealer-authorized source fields and purposes belong in the operational path.
Dealer-side cleaning is paired with independent intake screening before storage.
Accepted operational records remain bound to the authorized dealer context.
Third-party analytics, fingerprinting, and session recording are outside the public-site posture.
Storage and non-LLM processing are governed for Canada; any different inference path requires explicit disclosure.
Deployment evidence
These statements change as infrastructure changes. They should be verified from the exact environment, date, and scope before a dealer relies on them.
Evidence 01
Current provider settings, roles, tenant scoping, session controls, and enforcement evidence.
Evidence 02
Current service configuration, key ownership, rotation, and data-path evidence.
Evidence 03
Current backup scope, residency, restoration evidence, retention, and recovery testing.
Evidence 04
Current routing, headers, network boundaries, logs, and any cross-region processing.
Evidence 05
Dated test scope, result, remediation state, and limits of reliance.
Claim boundary
The absence of an unsupported claim is part of the security posture.
Next decision
The two-layer data-flow page shows the intended treatment of personal information and authorized operational fields.