Skip to content

Design-Partner Pilot

Evaluate

A good pilot proves one governed capability. It should not turn V1 into a broad agent platform, LLM gateway, plugin marketplace, managed MCP host, Terraform/operator project, or full DLP product.

  • Design partners evaluating fit.
  • Security and platform buyers scoping a first proof.
  • DAC operators preparing a pilot plan without publishing private GTM material.

This page is the public pilot framing. The design-partner path proves that one approved public target in managed mode, or one private target in self-hosted mode, can move through policy-filtered discovery, credential-safe routing, metadata-only audit, revocation, and deployment evidence.

Use it after a buyer can name:

  • one concrete private MCP server or API source;
  • allowed and denied access cases;
  • a non-production identity model or accepted simulation;
  • a credential binding reference or accepted mock;
  • audit/export expectations;
  • a deployment posture to review.

The public pilot frame tracks:

TrackEarly proofCloseout proof
CapabilityOne private MCP server or API source.One governed capability and one denied or hidden capability.
IdentityNon-production actor context or accepted simulation.Buyer-approved identity model for the pilot surface.
PolicyOne allow rule and one deny rule.Versioned policy and simulation output accepted by security.
CredentialsBinding reference or accepted mock.Secret-store integration path or customer-approved opaque handle model.
RoutingDirect private endpoint or connector-mode route.Route health, disable, and revoke behavior accepted.
AuditLocal metadata-only audit proof.SIEM/export path or accepted artifact.
DeploymentHelm render or sandbox install path.Managed or self-hosted checklist completed.

The demo path should show inventory, policy-filtered discovery, governed MCP call, selected API-to-MCP import, credential routing, session revoke, audit/export, and managed or self-hosted readiness.

  • The pilot tries to cover too many capabilities before one governed path works.
  • The customer needs production data migration, certified air-gapped packaging, local STDIO governance, managed MCP hosting, Kubernetes operator, Terraform module, ClickHouse, NATS, Kafka, Redpanda, full DLP, or prompt-injection detection. Those are outside the V1 pilot unless separately agreed and sourced.
  • Security cannot accept metadata-only evidence. That blocks the pilot because retained artifacts cannot contain raw payloads or secret material.
  • A public page exposes private account research, direct outreach copy, commercial terms, partner-specific content, or unreviewed claims. Keep that material out of public docs.

Type set in Geist, Source Serif 4, and Departure Mono.