Skip to content

Known limitations

This page lists current GaugeDesk limits. The status page is the source of truth for capability status.

Model inference

GaugeDesk does not run a model locally. It sends prompts and admitted context to the configured model provider in plaintext.

Current limits:

  • Confidential inference is not implemented.
  • Provider retention and training terms depend on the selected provider and account.
  • A local project can have unfiltered network access when the host cannot enforce the filtered route.
  • Network isolation can deny all network access, but that also prevents remote model inference.

Do not use data that cannot be sent to the selected provider.

Operating-system isolation

The method-isolation sandbox is available on Linux and macOS. Windows does not have the same kernel isolation.

Windows still uses application permission and network controls. These controls do not give the same method-confidentiality guarantee as the Linux/macOS sandbox.

Public deployments

The Theory A Embeddable Panels path is live as a production proof. It is not a general-availability commitment.

The full self-service journey is not yet accepted. It still needs one complete proof without founder action, from authoring through visitor collection and review.

GaugeWright does not promise an uptime SLA. The public runtime can operate without the author's computer or Home, but it still depends on GaugeWright's hosted edge services and the selected model provider.

Collection

Public-session collection is built and deployed. It has these limits:

  • The release must declare eligible paths or transcript collection before publication.
  • The release must declare a schema, recipient class, and size limit.
  • The deployment must select an exact recipient.
  • Collected content enters quarantine after drain.
  • GaugeDesk validates the artifact again before it can become admitted context.
  • A failed required deposit blocks terminal teardown until the effect settles or fails terminally.

The full customer journey is not yet accepted as self-service.

Federation

The federation protocol and blind relay are built and tested. Self-federation is available in its stated scope.

GaugeWright does not state that a general managed cross-party federation service is available. A CI or lab proof is not the same as a customer-operated production deployment.

Enterprise features

OIDC, SAML, SCIM, RBAC, audit, and GaugeDesk Administration are built. GaugeWright does not state that all enterprise features are generally available for customer tenants.

The company is founder-operated. Independent approval and separation of duties are not available.

Attested compute

The confidential-VM verifier and key-release seams are built. GaugeWright does not offer a generally available attested-compute service.

Attestation can remove the host operator from the plaintext trust set. It does not remove the model provider.

Availability and recovery

The hosted control plane is concentrated on one Azure virtual machine. Automatic multi-node failover is not implemented.

GaugeWright has:

  • encrypted backups;
  • a tested restore path;
  • an internal 24-hour recovery-point target; and
  • an internal 8-hour recovery-time target.

These are internal operating targets. They are not an uptime or recovery SLA. Restore evidence proves recoverability, not high availability.

Supply chain

GaugeWright active repositories run secret scanning, dependency audits, and static analysis where code executes. GaugeDesk and WhippleScript release workflows generate SPDX SBOMs and OIDC provenance attestations.

These controls do not provide independent assurance. A user must still verify the release source, artifact, signature or attestation, and platform-specific distribution status.

Privacy and compliance

GaugeWright publishes a privacy notice, a standard DPA, a subprocessor list, and a privacy request path.

GaugeWright does not have:

  • a completed independent penetration test;
  • a SOC 2 report;
  • ISO 27001 certification; or
  • independent internal approval.

Do not describe internal tests or formal models as third-party certification.

Mobile distribution

The iOS and Android clients are built and pass signed CI and hosted-device journeys.

The remaining limits include:

  • public app-store distribution;
  • production APNs and FCM delivery;
  • physical-device proof for all supported journeys; and
  • final platform-account and release operations.

Product and source distribution

The repository uses two license bands:

  • Apache-2.0 outside ee/; and
  • Business Source License 1.1 with the GaugeWright Enterprise Use Grant inside ee/.

Repository visibility and license are separate facts. Check the current repository and release page before you depend on public source or binary distribution.