WEB
Public site
Static pages, positioning, contact, and documentation. No workspace data required.
Security boundary
The live public site is static and informational. Workspace sessions, service credentials, action tokens, schedules, and artifacts belong in the private cockpit or infrastructure controlled by the user.
Boundary map
Static pages, positioning, contact, and documentation. No workspace data required.
Sessions, local database, source packs, provider keys, runs, approvals, and artifacts.
GPT Actions, MCP tools, webhooks, and service APIs only after explicit access rules exist.