What data reaches the LLM
An exact, agency-facing statement of what store information is sent to the AI provider that powers Reqursor's intelligence, and what is never sent, no exceptions.
When Reqursor's AI drafts a declaration or diagnoses a problem, it calls an external AI provider to do the reasoning. This page is the precise, complete answer to "what does that provider actually see?"
What's sent
| Category | Sent? | Why |
|---|---|---|
| Store declaration structure (design tokens, settings, features) | Yes | Needed to draft or check a valid declaration |
| Rules for your store platform (see How Reqursor works with your store platform) | Yes | Needed to keep AI output valid for the platform you use |
| Unexpected change evidence | Yes | Needed to diagnose a gap and propose a fix |
| Health status and check results | Yes | Needed for diagnostics |
| Failure evidence | Yes | Needed to explain what went wrong |
What's never sent, no exceptions
| Category | Sent? |
|---|---|
| Secret values (credentials, API keys) | Never |
| Business data (orders, customers, products) | Never |
| Infrastructure details (servers, internal networking) | Never |
| Another agency's data | Never |
| Full raw logs | Never |
One more rule: one agency per request
Every request to the AI provider is scoped to exactly one agency: never mixed, even if the AI needs to consider more than one of your own stores at once.
The provider doesn't even know who you are
Requests carry your agency's store data for that specific task, not your agency's identity as a named entity. There's nothing for the provider to connect back to a name, a brand, or a client list.
Why this matters for your agency
- Nothing you'd be uncomfortable with leaves the platform. Orders, customer records, and credentials are never part of what the AI sends anywhere.
- This isn't a promise; it's enforced at the technical level. What the AI can include in a request is constrained before the request is even sent, not left to judgment in the moment.
- Your data stays separate from other agencies. It's not architecturally possible for one agency's data to end up mixed with another's.
Where to go next
The AI-first security model
How this data boundary fits into Reqursor's overall security approach.
Security at a glance
The full picture: separate stores, secrets protection, AI safety, and checking every change.
How the AI writes your store's setup safely
What happens to the AI's recommendations after this data is analyzed.
The AI-first security model
Why a platform where AI helps run your stores faces security risks that traditional platforms never do, and how Reqursor Platform holds back every one of them.
Troubleshooting
What to do when a store has an unexpected change, a change fails, or something looks wrong, and what keeps running when something else breaks.