Public surfaces — documentation only
SDVM Privacy Policy
Last updated: 2026-07-29
This policy covers sdvm.tech (Gate 3 public landing) and the separate public SDVM Action Preview repository. It does not describe an available integrated diagnostic product. The External Product Readiness Gate remains BLOCKED — external diagnostic use and authorized diagnostic pilots are not available.
Surfaces in scope
- Landing (sdvm.tech) — public technical positioning; thesis, maturity, and collaboration pointers.
- Action Preview (ijamhour/SDVM-Action-Preview) — limited public-safe GitHub Action/CLI for evidence-shape validation and preview artifacts.
The Action Preview is not the target integrated diagnostic product, not integrated diagnosis, not an authorized pilot, not diagnostically valid PRE/POST/DELTA, and not Marketplace publication.
Summary
The Action Preview is designed to run in the operator’s own GitHub Actions runner or local environment on paths the operator supplies. It does not operate an SDVM-hosted multi-tenant SaaS backend for that preview path, and the public-safe preview package does not include default SDVM telemetry or centralized collection of workflow traces.
Hosting for sdvm.tech (for example Cloudflare Pages) and GitHub’s platforms apply their own terms, logs, retention, and security controls.
What may be processed
When an operator runs the Action Preview, it may read runner-local evidence files (such as canonical JSONL) and write local preview artifacts (validation and report files). Processing occurs in the operator’s environment for that preview path.
The operator is responsible for ensuring that any data used is authorized for that purpose and does not include secrets, credentials, private customer data, or sensitive payloads unless appropriate controls are in place.
What SDVM does not collect by default (Action Preview)
The public Action Preview package does not require sending traces, reports, credentials, or workflow data to a centralized SDVM-operated backend as part of normal Action execution.
GitHub, Cloudflare, and third parties
When the Action Preview runs on GitHub Actions, GitHub’s platform terms, logs, retention settings, permissions, and security controls may apply.
The landing site may be served via Cloudflare Pages or similar hosting; Cloudflare’s terms and logs may apply to site traffic.
Review repository settings, workflow permissions, retention policies, and organization policies before running the Action Preview on private or sensitive workflows.
Public Issues and collaboration
Public GitHub Issues on the Action Preview repository are a collaboration channel for non-confidential topics. Do not post secrets, credentials, private traces, customer data, or other confidential material in public Issues.
Opening an issue does not authorize a diagnostic pilot or promise integrated diagnosis.
Marketplace
Marketplace publication is not authorized. Any future publication would require External Product Readiness Gate pass, applicable Gate 4 requirements, and separate publication authorization.
Security and support
For Action Preview support and security guidance, use the public repository’s SUPPORT.md and SECURITY.md. Do not disclose sensitive security details in public Issues.
Changes to this policy
This policy may be updated as public surfaces evolve. Future versions may provide additional details if hosted services, telemetry, accounts, billing, or other platform capabilities are added.
Contact
For non-sensitive questions, use the public Issues channel: SDVM-Action-Preview collaboration Issues.
Do not disclose sensitive security details publicly.