Public surfaces — documentation only

SDVM Privacy Policy

Last updated: 2026-07-29

This policy covers sdvm.tech (Gate 3 public landing) and the separate public SDVM Action Preview repository. It does not describe an available integrated diagnostic product. The External Product Readiness Gate remains BLOCKED — external diagnostic use and authorized diagnostic pilots are not available.

Surfaces in scope

  • Landing (sdvm.tech) — public technical positioning; thesis, maturity, and collaboration pointers.
  • Action Preview (ijamhour/SDVM-Action-Preview) — limited public-safe GitHub Action/CLI for evidence-shape validation and preview artifacts.

The Action Preview is not the target integrated diagnostic product, not integrated diagnosis, not an authorized pilot, not diagnostically valid PRE/POST/DELTA, and not Marketplace publication.

Summary

The Action Preview is designed to run in the operator’s own GitHub Actions runner or local environment on paths the operator supplies. It does not operate an SDVM-hosted multi-tenant SaaS backend for that preview path, and the public-safe preview package does not include default SDVM telemetry or centralized collection of workflow traces.

Hosting for sdvm.tech (for example Cloudflare Pages) and GitHub’s platforms apply their own terms, logs, retention, and security controls.

What may be processed

When an operator runs the Action Preview, it may read runner-local evidence files (such as canonical JSONL) and write local preview artifacts (validation and report files). Processing occurs in the operator’s environment for that preview path.

The operator is responsible for ensuring that any data used is authorized for that purpose and does not include secrets, credentials, private customer data, or sensitive payloads unless appropriate controls are in place.

What SDVM does not collect by default (Action Preview)

The public Action Preview package does not require sending traces, reports, credentials, or workflow data to a centralized SDVM-operated backend as part of normal Action execution.

GitHub, Cloudflare, and third parties

When the Action Preview runs on GitHub Actions, GitHub’s platform terms, logs, retention settings, permissions, and security controls may apply.

The landing site may be served via Cloudflare Pages or similar hosting; Cloudflare’s terms and logs may apply to site traffic.

Review repository settings, workflow permissions, retention policies, and organization policies before running the Action Preview on private or sensitive workflows.

Public Issues and collaboration

Public GitHub Issues on the Action Preview repository are a collaboration channel for non-confidential topics. Do not post secrets, credentials, private traces, customer data, or other confidential material in public Issues.

Opening an issue does not authorize a diagnostic pilot or promise integrated diagnosis.

Marketplace

Marketplace publication is not authorized. Any future publication would require External Product Readiness Gate pass, applicable Gate 4 requirements, and separate publication authorization.

Security and support

For Action Preview support and security guidance, use the public repository’s SUPPORT.md and SECURITY.md. Do not disclose sensitive security details in public Issues.

Changes to this policy

This policy may be updated as public surfaces evolve. Future versions may provide additional details if hosted services, telemetry, accounts, billing, or other platform capabilities are added.

Contact

For non-sensitive questions, use the public Issues channel: SDVM-Action-Preview collaboration Issues.

Do not disclose sensitive security details publicly.