Security

Proof first. No unsupported compliance theater.

RecallOps avoids fake certifications and vague slogans. It shows identity gates, hashing, redaction, provider status, and tenant-write boundaries directly.

DETERMINISTICpacket digesta4a2fd3565b7d625...cb02ba893f487c04
GATEDIdentity

Approval identity is explicit.

Approval receipts bind signer, reason, scope, source hash, room hash, and filing hash. Public approval remains gated unless the configured identity path authorizes it.

DETERMINISTICHashing

Packets and receipts are digest-verifiable.

Source evidence, recall room output, filing pack, approval receipt, and final packet expose values that can be compared independently.

GATEDERP gates

Tenant writes are not implied.

SAP and Oracle actions remain dry-run or gated until customer endpoints and administrative authorization are configured.

LIVEProvider boundaries

Optional AI providers are disclosed.

Partner-AI paths run behind spend controls and response hashes. Deterministic parsing remains the public proof source of truth.

Public demo proves

Captured Band IDs, deterministic packet verification, source packet verification, SAP sandbox read verification, approval receipt hashing, ERP receiver receipts, and dry-run enterprise payloads.

Still requires authorization

Real customer ERP writes, production identity policy, tenant endpoint configuration, data-processing review, and regulator submission.

Status language

The label is part of the control.

LIVE

Created against the currently deployed external service.

CAPTURED

Recorded from an earlier real external interaction.

DETERMINISTIC

Reproduced locally from sealed demo data.

DRY RUN

Payload generated but not written to a tenant.

GATED

Action requires authenticated human or admin authorization.

SIMULATED

Demonstration-only behavior.