Product and engineering note · reviewed 10 September 2026
Privacy needs a data path, not just a policy
Trace source information, model requests, logs and retained results through a complete workflow.
Follow the information
A privacy statement describes an intention. A deployment needs an account of which information is read, transformed, transmitted, logged and retained. Start with the source records and follow each copy or representation to the service that processes it.
Separate the controls
Local execution, reduced disclosure and encryption solve different problems. A local application may still send requests to an external model. A transformed request can still reveal sensitive information. Permission controls should limit access and consequential actions; retention controls should describe what remains after the task.
Test the configuration
Use representative non-sensitive test data to inspect requests, logs and results. Review the provider configuration and failure behaviour, including what happens when a service is unavailable. Wave’s purpose is to prepare protected context for approved intelligence, but its actual data handling depends on the integration. Institutional deployments need configuration-specific evidence and qualified legal/security review.