AftercoreCAPACITY MARKETPLACE

CURRENT PILOT / DATA HANDLING

What Aftercore stores.

This describes the local implementation. A production operator's identity, contact details and jurisdiction-specific privacy terms have not been configured; broad public enrollment is not open.

Accounts and credentials

Account email, a salted password hash, session hashes and API key hashes are stored in PostgreSQL. Provider credentials are encrypted at rest with the application key; engine credentials use their own encrypted store. The web app does not receive the operator's payout signing key.

When the production proxy is configured, network rate limits use keyed hashes of client IP addresses. Raw addresses are not retained in these counters or default access logs. Key creation and rotation timestamps enforce a shared account limit. This does not change the financial or provider records retained below.

Inference

Prompts and responses pass through Aftercore and the selected provider. Normal application accounting stores request/response identifiers, supplying seat, buyer, price version, status, timing, body hash, token counters and financial entries. It does not intentionally archive normal request or response bodies. Default engine conversation archives and telemetry are disabled.

A separately authorized Grok diagnostic retained an encrypted response to investigate stream framing. That acceptance artifact and its recovery evidence remain in the local encrypted database/backup; this is not a zero-retention product. Vendor processing and retention are governed by the relevant account and provider settings and have not been independently audited by Aftercore.

Payments and support

Verified wallet addresses, ownership messages, transaction hashes, ledger entries and encrypted signed payout transactions support accounting and recovery. Blockchain transactions are public. Private support messages are encrypted in the database and readable by their account owner and authorized operators. Avoid including keys, passwords or complete prompts.

Retention and removal

The worker removes expired session hashes after one day and expired login/network-rate buckets after seven days, in bounded batches. Expired pending connection secrets are cleared. Revoking a source removes its live credential copy; encrypted backups may retain earlier copies.

Financial records, request metadata, support conversations, operator audits, acceptance evidence and encrypted backups are retained during the pilot. No automatic erasure deadline or account-deletion workflow is promised. Request a review through private support; records required to reconcile existing funds must be handled explicitly. Backups and their separate recovery key still require offsite custody.

Access

Buyer APIs are scoped to their authenticated account. Operators can inspect bounded operational metadata and support tickets; credential export is not available through their web interface. Management engines remain private. Security tests establish particular checked behaviors, not certification.

Open private support ↗