No secrets in first contact
Do not send API keys, passwords, payment card data, private customer records, credential files, executable files, or unverified attachments in the first request.
Evidence handling and privacy boundary
Bluebutterfli AI reviews live AI agent behavior after scope approval. The first contact should use safe text only. Sensitive material, credentials, customer data, raw transcripts, and private operational records are not requested in the first review request.
Core principles
The goal is to make evidence useful for review without exposing private customer material or pretending a public hash is a safety guarantee.
Do not send API keys, passwords, payment card data, private customer records, credential files, executable files, or unverified attachments in the first request.
Live evaluation access is confirmed only after agent ownership, authorization, workflow scope, and safe handling expectations are clear.
Customer-facing reports use summaries, redacted excerpts, reviewer notes, and risk findings instead of raw sensitive material.
Raw transcripts, customer files, reviewer notes, and sensitive operational evidence are not published on-chain.
Optional public-safe hashes or manifests can show that an artifact existed without exposing the private content itself.
Passport status, review stamps, public summaries, and retest results require human review and do not follow automatically from payment or submission.
Evidence flow
Bluebutterfli AI separates the intake, live evaluation, private evidence, redacted report, and optional public verification layers.
The customer provides safe text, owner authorization, agent context, and live access notes without secrets.
Bluebutterfli confirms review package, workflow, access method, boundaries, and first test path.
Approved prompts or agreed evidence are evaluated against the scoped agent version and workflow.
Reviewer notes and observations are organized into findings, limitations, severity, and retest triggers.
The customer receives a report, risk scorecard, revision plan, retest checklist, and Passport record when applicable.
If scoped, public-safe manifests or hashes can reference artifacts without exposing private evidence.
First-contact checklist
Evidence boundary
This page describes Bluebutterfli AI review handling boundaries. It is not legal advice, a privacy certification, a cybersecurity certification, regulatory approval, or a guarantee of safety. Enterprise customers may require separate agreements, legal review, security review, or privacy review before sensitive work begins.