Shape
Advisory context only. It does not block customer traffic.
Platform / Security
The customer data plane, attribution graph, index, decision records, and decision-time interceptor are designed to run inside the customer environment. Connectors are read-only; data crossing into the Venturi control plane is limited and explicitly enumerated.
Security claims are labeled by state: specified, implemented, tested, independently assessed, or planned.
Trust-boundary diagram
Narrow deployment and health metadata may cross the boundary as explicitly listed below. Optional aggregated benchmarking is a separate opt-in.
Trust boundary
Customer operational data remains inside the customer-controlled data plane.
Narrow deployment and health metadata may cross the boundary only as listed.
Optional aggregated benchmarking is a separate explicit opt-in.
In summary: read-only connectors, governed records, graph, index, attribution engine, decision records, and interceptor run in the customer environment. Only the listed tenant, version, license, configuration, connector identifier, and health metadata may cross to the Venturi control plane. Customer operational content is explicitly excluded.
What runs where
The control plane manages narrow licensing, version, configuration, and health concerns. It is not the customer attribution data plane.
What may cross the boundary
Each allowed field has a deployment or diagnostic purpose. Source payloads and customer operational content are not implied by these categories.
Read-only permission matrix
Venturi asks for the narrowest source scope that can support the approved relationships. Any scope expansion returns to security review.
Fail-open diagnostic
Timeout, service error, index unavailability, connector degradation, policy lookup failure, and confidence below threshold produce operator evidence while the request proceeds unmodified.
Fail-open diagnostic
Shape and customer-controlled Gate
Shape supplies context, review routing, and optimization recommendations. Gate is a separate customer-controlled path and is never activated by low-confidence ownership.
Advisory context only. It does not block customer traffic.
A customer-controlled Gate path may act only for explicitly configured workloads and policies. Venturi failure always forwards customer traffic.
Negative capabilities
These boundaries narrow the permission and data surface a reviewer needs to evaluate.
Control-status roadmap
Specified, implemented, tested, independently assessed, and planned are separate states. The table states what evidence is still required before a stronger external claim is allowed.
| Control | Current state | Evidence required | External claim allowed |
|---|---|---|---|
| Customer data-plane boundary | Specified | Deployment review and production validation | Architecture commitment |
| Read-only connector scope | Specified | Connector permission review and production validation | Architecture commitment |
| Fail-open decision path | Specified | Implementation evidence, fault tests, and production validation | Architecture commitment |
| SOC 2 Type I | Planned | Completed readiness work and independent audit report | Planned only |
| SOC 2 Type II | Planned | Type I completion, observation period, and independent audit report | Planned after observation period |
| ISO 27001 | Planned | Customer demand, implemented ISMS, and certification audit | Future based on customer demand |
| DPA and subprocessor documentation | Planned | Counsel-approved documents and maintained inventory | Planned only |
| Data-subject workflows | Planned | Counsel-approved process and exercised request handling | Planned only |
Security-review request
The request path covers the trust-boundary diagram, control-plane metadata inventory, permission matrix, fail-open diagnostic, negative capabilities, and current control-status roadmap.