Trust
Isolation model
The coordinator signs assignments and the provider app verifies the signature before execution. Inputs pass through an HTTPS-only download gate that rejects private network destinations.
Provider execution receives the plaintext needed for its assigned task. App sandboxing, process separation, and cleanup reduce risk but do not make the system provider-blind.
- Use only data appropriate for execution on an independently operated provider device
- Do not submit regulated or highly sensitive data that requires a DPA or provider-blind processing
- Use the dashboard deletion workflow for supported account and job records