Privacy Policy
This Privacy Policy describes how FortressCodeAI handles information related to BaseLayerOS, enterprise packs, deterministic substrate provisioning, and governance envelope integrations. This policy applies to all interactions with BaseLayerOS and the enterprise marketplace.
1. Information We Collect
FortressCodeAI collects only the information necessary to provide deterministic substrate services, enterprise onboarding, and governance envelope validation. This may include:
- Organization and contact information provided during onboarding.
- Technical metadata required for substrate provisioning.
- Logs generated by BaseLayerOS during deterministic execution.
- Audit traces associated with validated governance envelopes.
FortressCodeAI does not collect or store:
- AI model outputs or prompts.
- Governance engine decisions (these remain with the external engine).
- Customer data accessed through envelopes (BaseLayerOS sees only envelope metadata).
2. Governance Envelope Privacy
BaseLayerOS validates envelopes produced by external governance engines (e.g., May I AI) using the Kali Standard Envelope Schema. Envelopes contain metadata such as identity, capability, invariants, and execution plans. BaseLayerOS does not access or store underlying customer data referenced by those envelopes.
3. Deterministic Execution Logs
BaseLayerOS generates deterministic logs and replayable traces for audit and compliance purposes. These logs contain:
- State transitions
- Invariant checks
- Envelope validation results
- Execution outcomes (commit or refusal)
Logs do not contain customer data, PHI, financial records, or AI model content.
4. Enterprise Pack Data
Enterprise packs (Governance, AI Safety, Healthcare, Finance, Foundations) may require organization‑specific configuration details. These details are used solely for deployment and are not shared with third parties.
5. Data Sharing
FortressCodeAI does not sell, rent, or share customer information. Data may be shared only:
- With the customer’s explicit authorization.
- As required by law or regulatory mandate.
- To fulfill enterprise procurement or contractual obligations.
6. Security
BaseLayerOS uses deterministic cryptographic seals, invariant enforcement, and secure substrate boundaries to ensure that governance envelopes and execution traces remain tamper‑evident and auditable. Enterprise deployments may include additional security controls based on sector requirements.
7. External Governance Engines
External governance engines (including May I AI) operate independently. FortressCodeAI does not control their data handling practices. Customers should review the privacy policies of any governance engine integrated with BaseLayerOS.
8. Changes to This Policy
FortressCodeAI may update this Privacy Policy to reflect changes in substrate capabilities, enterprise offerings, or regulatory requirements. Continued use of BaseLayerOS constitutes acceptance of updated terms.
9. Contact
For privacy inquiries or enterprise compliance questions:
fortresscodeai@outlook.com