Security boundary
A narrow product is easier to defend.
DeltaChime is in validation. The public demo uses fictional fixtures and makes no outbound source requests; production capture has a separate release gate.
Public sources only
Coverage is limited to approved public commercial pages. No customer cookies, no authenticated browsing sessions.
No access-control bypass
No CAPTCHA, challenge or robots bypass. A blocked source stays blocked or moves to manual review.
Evidence remains data
Captured HTML and model output are untrusted. Customer views render escaped text and structured values, never source markup.
Production capture stays locked
Live retrieval remains disabled until DNS pinning, redirect checks, response limits and isolated execution pass adversarial tests.
Report a security issue
Send a concise description and reproduction steps to security@deltachime.io. Leave out secrets or personal data the report does not need.