{
  "updated": "2026-08-08",
  "notes": "Truth labels for public claims. Supported means tested text-send paths with an operational owner. Preview is pilot-only. Planned has no customer guarantee. Unsupported must be stated where buyers could assume coverage. Claude Code via ANTHROPIC_BASE_URL → /v1/messages is Supported; Codex openai_base_url scrub-forward is Preview (not durable OpenAI enforcement). SharePoint site sweep and mailbox search are Planned connectors that call document:scan — not Browser Guard and not transparent Graph interception. Google AI Studio and NotebookLM Browser Guard adapters are Planned — Gemini web alone is Preview; do not claim all Google AI is covered. See docs/GOOGLE_AI_BROWSER_PLAN.md.",
  "states": {
    "Supported": "Automated tests, documented boundary, operational owner — may appear as available.",
    "Preview": "Works for named pilot paths; support/evidence incomplete — label clearly.",
    "Planned": "Approved backlog with no customer guarantee — roadmap only.",
    "Unsupported": "No reliable protection or explicit non-goal."
  },
  "surfaces": [
    {
      "surface": "ChatGPT web in managed Chrome/Edge",
      "integration": "Browser Guard",
      "boundary": "Text submitted through tested composers and send paths",
      "status": "Supported"
    },
    {
      "surface": "Claude web in managed Chrome/Edge",
      "integration": "Browser Guard",
      "boundary": "Text submitted through tested composers and send paths",
      "status": "Supported"
    },
    {
      "surface": "Gateway API / SDK",
      "integration": "Data-plane API and provider-compatible proxy",
      "boundary": "Request bodies sent through the declared endpoint/proxy contract",
      "status": "Supported"
    },
    {
      "surface": "Private appliance",
      "integration": "Docker Compose (pilot) / Helm (production)",
      "boundary": "Same engine, policy, API and audit model under customer control",
      "status": "Supported"
    },
    {
      "surface": "Claude Code / Anthropic SDKs (Windows, macOS, Linux)",
      "integration": "Native installer (.exe / .app/.dmg) sets ANTHROPIC_BASE_URL → sdlc gateway (not api.anthropic.com)",
      "boundary": "Model calls that honor the installer-set env with a messages-scoped sk_sdlc_* key; public .exe/.app on /downloads/claude-code/; key via activation; signed MSI / notarized DMG Planned; streaming is buffered SSE; Claude Desktop GUI may not honor env",
      "status": "Supported"
    },
    {
      "surface": "Codex / OpenAI-shaped clients (CLI, IDE)",
      "integration": "Native installer sets openai_base_url → https://api.sdlc.cc/v1; gateway scrub-forwards /v1/responses and /v1/chat/completions",
      "boundary": "Preview scrub-forward only — not Supported durable enforcement. Host needs OPENAI_API_KEY; refuses stream:true, images/files, and legacy /v1/completions; CF worker and explicit scrub remain alternate Preview paths",
      "status": "Preview"
    },
    {
      "surface": "Desktop Guard secure composer",
      "integration": "HTML secure composer Preview (paste, local plain-text open, sanitize)",
      "boundary": "Content pasted or opened as local UTF-8 text through sdlc.cc, then copied into AI/email; ordinary native chat input and AI-site file uploads are not intercepted; PDFs/Office/images/voice unsupported; signed OS companion is future work",
      "status": "Preview"
    },
    {
      "surface": "Selected M365 Office / Teams utilities",
      "integration": "Explicit Sanitize for AI action (Outlook, Word, Excel, Teams)",
      "boundary": "Manual sanitize on selected text/content; no automatic Copilot interception",
      "status": "Preview"
    },
    {
      "surface": "Gemini web in managed Chrome/Edge",
      "integration": "Browser Guard adapter",
      "boundary": "Tested text composer only; uploads/images excluded. Promotion to Supported needs partner drill — see docs/GOOGLE_AI_BROWSER_PLAN.md Phase A",
      "status": "Preview"
    },
    {
      "surface": "Google AI Studio web in managed Chrome/Edge",
      "integration": "Browser Guard adapter (planned)",
      "boundary": "Planned text-composer intercept on aistudio.google.com; uploads/images/voice excluded until separately proven",
      "status": "Planned"
    },
    {
      "surface": "NotebookLM web in managed Chrome/Edge",
      "integration": "Browser Guard adapter (planned)",
      "boundary": "Planned text-composer intercept on notebooklm.google.com; notebook source uploads, Drive imports, and audio overviews excluded until separately proven",
      "status": "Planned"
    },
    {
      "surface": "Firefox",
      "integration": "WebExtension build from the same client core",
      "boundary": "Tested supported web composers after conformance",
      "status": "Preview"
    },
    {
      "surface": "Transparent native-app interception",
      "integration": "Not the default product path",
      "boundary": "Ordinary native ChatGPT/Claude/Gemini prompts without secure composer",
      "status": "Unsupported"
    },
    {
      "surface": "Uploads, images, and voice",
      "integration": "Out of MVP text-send scope",
      "boundary": "AI-site file/image/voice inputs are not protected. Desktop Guard and scrub.sdlc.cc may open local plain-text exports only — not PDF/Office/binary uploads",
      "status": "Unsupported"
    },
    {
      "surface": "SharePoint / OneDrive document scan connector",
      "integration": "TenantIQ Graph adapter → POST /v1/documents/scan (connector pack in admin)",
      "boundary": "sdlc.cc API and admin pack are ready; TenantIQ owns Graph extract. Extracted text only; no automatic SharePoint edits",
      "status": "Planned"
    },
    {
      "surface": "Mailbox search / email analysis connector",
      "integration": "TenantIQ Graph adapter → POST /v1/documents/scan (connector pack in admin)",
      "boundary": "sdlc.cc API and admin pack are ready; TenantIQ owns mailbox/search extract before AI research; not mail-flow DLP",
      "status": "Planned"
    },
    {
      "surface": "SSO / SCIM enterprise identity",
      "integration": "Identity adapters",
      "boundary": "SAML/OIDC and SCIM provisioning",
      "status": "Planned"
    },
    {
      "surface": "HA / SLA commercial guarantees",
      "integration": "Hosted operations contract",
      "boundary": "Formal availability SLAs and multi-region HA promises",
      "status": "Planned"
    },
    {
      "surface": "Public store marketplace approval",
      "integration": "Chrome Web Store / Edge Add-ons / Microsoft marketplace",
      "boundary": "Certified public listing and store review outcomes",
      "status": "Planned"
    },
    {
      "surface": "Copilot Graph sweeping",
      "integration": "Microsoft Graph / Copilot data plane",
      "boundary": "Automatic sweeping or interception of Copilot Graph traffic",
      "status": "Unsupported"
    }
  ]
}
