The public bootstrap contains no production service and accepts no user documents.
The hosted Lab design must initially accept only public, synthetic, or non-confidential samples. It must reject confidential, privileged, regulated, export-controlled, and classified content until the corresponding security profile is reviewed and approved.
Security reports should not include confidential customer documents or raw proprietary policy text.