01 · Model training

Customer code is not used to train any AI.

A customer's source code, technical maps, indexes and derived representations are not used to train, fine-tune or improve models shared with other customers.

02 · CUSTOMER ISOLATION

The investigation works with technical maps, indexes and derived representations that are isolated by customer. This context remains linked to that customer's environment and does not become shared knowledge in a model.

Security boundaries

Access, approval and review remain explicit.

03 · READ-ONLY CODE ACCESS

Read-only Git access

The Git provider access used for the investigation is read only.

04 · NO CODE CHANGES

No edits to repositories

RefineBrief does not edit files, create branches, commit, push or open pull requests.

05 · JIRA APPROVAL

Jira tickets only after approval

Jira tickets are created only after explicit approval by the user.

06 · EVIDENCE AND REVIEW

Evidence, inferences and questions remain separate

RefineBrief keeps discovered evidence, reasonable inferences and unanswered questions visibly separate for team review.

Security review

Review the access boundary before connecting a repository.

Use a real product idea and the actual customer setup in the security conversation.