Trust
What we do with what you send us
Data handling depends on the screening and retention controls configured for your deployment. We confirm those settings, access rules and operational details in writing.
Ordinary storage
Contributions are screened before ordinary storage. What is detected depends on the configured screening tools, so screening reduces exposure but does not guarantee removal of every sensitive detail.
The managed record can include the proposed guidance and the context needed to review it: its source agent or task, when it was submitted and who submitted it.
Optional review-vault storage
Where the review vault is enabled, restricted original values or quarantined corrections may be retained under its access and retention policy. Where it is disabled, that additional vault storage is not available.
We confirm whether the vault is enabled, who can access it and how long retained material is kept for the deployment in scope.
Screening
Contributions are checked for supported personal-data patterns and prompt injection. Depending on the configured policy and detected issue, a contribution can be masked, held, quarantined or rejected.
These controls should be assessed alongside your own data-handling policy and testing. They are not a promise that every sensitive value or malicious instruction will be detected.
Separation
Each organisation’s guidance is held separately. Within an organisation, configure teams and access so published guidance reaches the intended audience; scoping is not automatic least-privilege distribution.
Delivery and availability
Published skills can be installed as files in an agreed environment. Agents can keep reading those installed files while OMS is unavailable, although corrections and updates wait for the connection to return.
Agents retrieving skills over MCP depend on OMS being available for that request. Availability requirements therefore depend on the delivery route you choose.
Deployment facts to confirm
Certification status, sub-processors, hosting and processing regions are operational facts, not product-copy assumptions. Ask for the current written position for the deployment you are evaluating.
What this page does not claim
OMS does not make you compliant on its own, and it does not explain what a model was thinking. It gives you evidence about guidance: what existed, where it came from, who approved it, and when it changed.