Read-only first
Begin with permitted observation. External action is outside the default authority boundary.
Security & permissions
Rootspan’s current design-partner workflow is supervised and read-only by default. The evidence needed for a diagnostic is intentionally narrower than a merchant’s full operating data.
Control model
Begin with permitted observation. External action is outside the default authority boundary.
Scope evidence to the merchant, systems, and fields needed for the diagnostic.
Keep source identity, timestamps, and hashes without copying raw values into logs or analytics.
Describe the exact field, basis, affected entities, uncertainty, rollback, and verification plan.
Keep the accountable operator between a proposal and any future external write.
Retain safe receipts and transition records so the case can be reconstructed.
Excluded data
Passwords, API secrets, or credentials
Payment, card, or banking information
Customer names, addresses, or order-level PII
Unredacted exports in the website inquiry
Advertising audiences or bidding data
Pilot lifecycle
Exact pilot terms are agreed before any permitted material is provided.
Document sources, permissions, exclusions, retention intent, and accountable contacts.
Use references and redacted events; keep evidence access scoped and time-bound.
Revoke access, honor the agreed deletion path, and retain only approved audit facts.
Security contact
Send vulnerability reports and security concerns to security@rootspan.ai. Do not send credentials, customer data, or active exploit payloads in an initial message.
Email security@rootspan.ai ↗View security.txt ↗