AXIASPHERE
Zero-content retention
LIVING PRODUCT MAP · v0.9.4

AxiaSphere system map.

This page mirrors the controlled documentation in docs/PRODUCT_SYSTEM_MAP.md. Status labels are intentionally conservative and never imply independent assurance that has not occurred.

LIVE

Public Web

axiasphere.com · marketing, public-source risk, documentation

LIVE

Workspace Shell

Command Center, Portfolio, Scenario Lab and Sphere View on controlled preview

LIVE

Memory-only Portfolio

Browser-tab state only; no holdings upload or browser-content persistence

LIVE

Encrypted Workspace

AES-256-GCM user-controlled .axiasphere export/import

LIVE

Hostname Boundary

Next.js Proxy separates public/app/Ops and fails protected custom hosts closed

STAGED

Operations Shell

Privacy-safe control plane; production Ops authentication remains fail-closed

STAGED

Operations Telemetry

Aggregate-only no-store adapter implemented; approved external endpoint not connected

STAGED

SOC 2 Readiness

Control roadmap and evidence model documented; no attestation or certification claim

BLOCKED

Identity / AAL2

Production app hostname remains 503 until a real session verifier is implemented

BLOCKED

Licensed Market Data

Provider contracts, entitlements and provenance adapter pending

STAGED

AI Committee

Policy/cost/redaction architecture documented; provider activation pending

CUSTOMER CONTENT BOUNDARY

Private work stays outside Operations.

User device
holdings · research · encrypted files
→ transient computation →
AxiaSphere runtime
no customer-content persistence
→ approved metadata only →
Operations
aggregate health/security/usage only
OPERATIONS TELEMETRY BOUNDARY

Observe the service, not the customer.

Approved observability
aggregate counters + health
→ HTTPS / no-store →
Allowlist adapter
numeric fields only
→ display only →
Ops dashboard
requests · errors · latency · counts
Explicitly excluded: holdings, prompts, searches, documents, report contents, request paths and customer identifiers.