Security & data handling

Bound the work before access begins.

BitEvo performs bounded engineering assurance and implementation work for consequential AI-agent and software workflows. This page explains the operating boundary visible on the public site; engagement-specific data handling is frozen separately in the SOW and Rules of Engagement.

01

Staging/test by default

Public scope preparation does not authorize testing. Production effects require separately agreed written scope and Rules of Engagement.

02

Minimum necessary access

BitEvo asks only for the access and evidence needed for the bounded workflow or control being tested.

03

No secrets in public intake

Do not submit passwords, API keys, private keys, wallet seeds, production credentials or unnecessary customer secrets through public forms/tools.

04

Stop on ambiguity

Unexpected production effects, unclear scope or unsafe provider behavior are stop conditions rather than reasons to continue testing.

05

Evidence with limitations

Results preserve what was observed, what was inferred, what was not tested and what owner decision the evidence supports.

06

Bounded claims

A passing scenario is not certification, universal safety, defect absence or proof that every tool path is controlled.

Evidence handled in scope

Collect what the decision needs — not everything available.

Depending on the engagement, evidence may include logs, request/response traces, configuration snapshots, screenshots, test identifiers, downstream readback and integrity hashes/manifests where applicable. The exact set, retention expectations and access path belong in the written engagement scope.

Public intake boundary

Do not paste credentials or sensitive secrets.

The public intake prepares a scope brief only. It is not an authorization channel for testing and is not the place to transmit production credentials or unnecessary customer data.

Professional boundary

Engineering evidence, not certification.

BitEvo does not present a bounded engineering review as a statutory/accredited audit, legal opinion, full penetration test, or guarantee of security, compliance, uptime or absence of unknown defects.

Before testing

Scope · authorization · access · stop conditions.

Those four elements are part of the evidence chain. Testing begins only after the engagement boundary is explicit.

Prepare the boundary