Policy
Sandbox & demo data policy
DRAFT · not reviewed by a lawyer. Version 2026-10-05.draft-1. This text is a good-faith description of how the early preview works, written by the operator. It is not legal advice, not a compliance statement under any regime, and will change after counsel review. If anything here conflicts with how the service actually behaves, the behaviour described in the public code and rulebook is what happens.
- What the sandbox is: a throwaway operator, agent and two environments on
*.sandbox.exampleorigins (which never resolve), created byPOST /sandbox/start. Its demo private keys sit server-side in KV and expire after 24 hours. Real operators never hand keys to the registry. - Labelling: sandbox environments carry
ownership: "sandbox"and “DEMO SANDBOX ORIGIN” everywhere they appear. A sandbox passport is not an official credential and its share card says so. - Permanence: passports, audit entries, stamps and log leaves created by the sandbox are permanent, like everything else in the append-only tables. They are not deleted, “cleaned up” or rewritten; they stay labelled.
- Operator test traffic: smoke tests and capacity benchmarks run by the operator use sandbox sessions only (label e.g.
write-bench), never real origins or money. - Abuse limits: 8 sandbox starts per minute per IP, 120 writes per minute per IP. The operator may switch the sandbox off (
ENABLE_SANDBOX=0) at any time, for example before inviting the public at large. - Reputation: sandbox environments count zero toward reputation breadth.