CrateSphere policy
AI development data policy
The boundary that keeps customer and runtime data out of general-purpose AI-assisted product development.
Last updated: 24 August 2026
1. Core commitment
CrateSphere uses general-purpose AI assistance only in segregated source checkouts containing source code and synthetic, deliberately sanitised fixtures. Customer data, label media, credentials, production diagnostics, live production systems and external storage are outside that boundary.
This restriction applies regardless of AI provider, account tier, retention setting or stated training policy. Those settings can be useful safeguards, but they are not treated as proof of isolation.
2. What AI-assisted development may access
AI-assisted work may use application source code, dependency manifests, tests and artificial fixtures that contain no customer information. Reports and screenshots supplied for development must be deliberately sanitised. Support examples use synthetic data or a narrow, redacted allowlist rather than raw exports or production logs.
3. What it may not access
AI-assisted development must not access, read, search, summarise, upload or transform customer databases, database dumps, credential vaults, environment files, external keys, runtime directories, storage roots, uploads, backups, logs or support bundles. Ignored files are not treated as an access-control boundary.
If runtime or customer material is discovered in an AI-visible checkout, its content is not inspected. A human must move it to separately permissioned storage before work continues.
4. Production separation
AI-assisted development sessions do not connect to production hosts, production databases, private object storage, secret managers or customer credentials. Development and diagnostic work uses a dedicated development identity with no route or credentials to those systems.
5. Future specialist machine-learning features
A specialist machine-learning feature that processes customer data would be a separate, opt-in service. Before any such feature is offered, CrateSphere will document the customer consent model, contract terms, retention period, subprocessors and technical controls. It will not be silently enabled through general development tooling.
6. Questions and reports
For questions about this policy, email admin@cratesphere.org. To report a security concern, email security@cratesphere.org.