Evidence handling and privacy boundary

Private Evidence Stays Private. Public Proof Stays Bounded.

Bluebutterfli AI reviews live AI agent behavior after scope approval. The first contact should use safe text only. Sensitive material, credentials, customer data, raw transcripts, and private operational records are not requested in the first review request.

Core principles

How Review Evidence Is Treated

The goal is to make evidence useful for review without exposing private customer material or pretending a public hash is a safety guarantee.

01

No secrets in first contact

Do not send API keys, passwords, payment card data, private customer records, credential files, executable files, or unverified attachments in the first request.

02

Scope before access

Live evaluation access is confirmed only after agent ownership, authorization, workflow scope, and safe handling expectations are clear.

03

Redaction before reporting

Customer-facing reports use summaries, redacted excerpts, reviewer notes, and risk findings instead of raw sensitive material.

04

Private evidence off-chain

Raw transcripts, customer files, reviewer notes, and sensitive operational evidence are not published on-chain.

05

Public proof is limited

Optional public-safe hashes or manifests can show that an artifact existed without exposing the private content itself.

06

Human review before status

Passport status, review stamps, public summaries, and retest results require human review and do not follow automatically from payment or submission.

Evidence flow

From Safe Intake to Review Report

Bluebutterfli AI separates the intake, live evaluation, private evidence, redacted report, and optional public verification layers.

  1. 01Safe request

    The customer provides safe text, owner authorization, agent context, and live access notes without secrets.

  2. 02Scope approval

    Bluebutterfli confirms review package, workflow, access method, boundaries, and first test path.

  3. 03Live testing

    Approved prompts or agreed evidence are evaluated against the scoped agent version and workflow.

  4. 04Evidence review

    Reviewer notes and observations are organized into findings, limitations, severity, and retest triggers.

  5. 05Redacted report

    The customer receives a report, risk scorecard, revision plan, retest checklist, and Passport record when applicable.

  6. 06Optional public proof

    If scoped, public-safe manifests or hashes can reference artifacts without exposing private evidence.

First-contact checklist

What to Send First

Good first details
Agent name, owner, requester authorization, workflow summary, intended users, known concerns, desired review package, and safe live access notes.
Do not send first
Secrets, API keys, passwords, private customer records, payment card data, credential files, executable files, raw sensitive transcripts, or unverified attachments.
After scoping
Bluebutterfli can confirm whether a staging account, demo agent, screen-share, API connector, or concierge sandbox is appropriate.

Evidence boundary

Evidence Handling Is Not a Compliance Certification

This page describes Bluebutterfli AI review handling boundaries. It is not legal advice, a privacy certification, a cybersecurity certification, regulatory approval, or a guarantee of safety. Enterprise customers may require separate agreements, legal review, security review, or privacy review before sensitive work begins.