{"ok":true,"reviewer":"CLO","product":"Glint","entity":"AurumFlux AI, Inc.","reviewed_at":"2026-09-19T11:44:54.627852+00:00","terms_version":"2026-07-06-glint-v2","verdict":"LAUNCH_READY_PILOT","grade":"B+","summary":"Glint may run **paid pilot with 3 free agency scans** once Shopify GDPR webhooks are registered and human confirms insurance/DPA posture. **Not ready for App Store listing or enterprise agencies** until L08 + L09 closed.","launch_gate":{"pilot_free_scans":true,"paid_strangers":true,"shopify_app_store":false,"enterprise_agencies":false},"counts":{"implemented":7,"partial":5,"blockers":3},"critical_blockers":[],"high_priority_open":[{"id":"L09","area":"GDPR / CCPA — agency + end-client data","status":"partial","risk":"high","note":"Privacy policy lists rights. Agency is controller for client merchant data; AurumFlux is processor. DPA available on request.","owner":"CLO","action":"Prepare signed DPA template (GDPR Art. 28) for EU/UK agencies"}],"checklist":[{"id":"L01","area":"Product-specific Terms of Service","status":"implemented","risk":"critical","note":"Glint ToS at https://glint.aurumflux.co/glint/terms — covers agency relationship, execute authority, liability caps.","owner":"CLO"},{"id":"L02","area":"Product-specific Privacy Policy","status":"implemented","risk":"critical","note":"Glint Privacy at https://glint.aurumflux.co/glint/privacy — Stripe/Shopify token custody, subprocessors, retention.","owner":"CLO"},{"id":"L03","area":"Client authorization (agency → merchant)","status":"implemented","risk":"critical","note":"Template at https://glint.aurumflux.co/glint/client-auth. Agency must collect before connecting client keys.","owner":"CLO"},{"id":"L04","area":"Registration consent (ToS + Privacy acceptance)","status":"implemented","risk":"high","note":"register_agency requires accepted_terms=true and matching terms_version.","owner":"CTO"},{"id":"L05","area":"BondPermit ToS alone is insufficient","status":"pass","risk":"critical","note":"BondPermit terms cover permit research only — not payment-system access or billing remediation.","owner":"CLO"},{"id":"L06","area":"PCI DSS scope","status":"pass_with_conditions","risk":"medium","note":"Glint uses Stripe APIs/keys — does not store PAN. Maintain SAQ A via Stripe. Never log full rk_ keys.","owner":"CIO"},{"id":"L07","area":"Stripe restricted key / Connect compliance","status":"pass_with_conditions","risk":"high","note":"Agency must have client authorization. Read-only default. Write scopes documented in upgrade flow.","owner":"CLO"},{"id":"L08","area":"Shopify Partner app + GDPR webhooks","status":"pass_with_conditions","risk":"high","note":"GDPR webhook handlers implemented (customers/redact, shop/redact, data_request). Must register URLs in Shopify Partner Dashboard before App Store listing.","owner":"CTO","action":"Register webhook URLs in Shopify Partner app"},{"id":"L09","area":"GDPR / CCPA — agency + end-client data","status":"partial","risk":"high","note":"Privacy policy lists rights. Agency is controller for client merchant data; AurumFlux is processor. DPA available on request.","owner":"CLO","action":"Prepare signed DPA template (GDPR Art. 28) for EU/UK agencies"},{"id":"L10","area":"Data deletion (right to erasure)","status":"implemented","risk":"medium","note":"POST /glint/legal/delete-account (authenticated agency) wipes agency row, clients, tokens, actions.","owner":"CTO"},{"id":"L11","area":"Subscription auto-renewal disclosure (CA/NY/etc.)","status":"implemented","risk":"medium","note":"ToS §4 discloses $299/$499 recurring, cancel via Stripe portal, renewal terms.","owner":"CLO"},{"id":"L12","area":"Not financial / legal / accounting advice","status":"implemented","risk":"medium","note":"Disclaimers on site + ToS. $-at-risk is operational estimate not audited financial statement.","owner":"CLO"},{"id":"L13","area":"AI disclosure","status":"pass","risk":"low","note":"Scanners are rule-based API checks, not generative AI on payment data. No AI training on client credentials.","owner":"CLO"},{"id":"L14","area":"Cyber liability / E&O insurance","status":"not_verified","risk":"medium","note":"Product handles write access to client billing systems — cyber E&O recommended before scale.","owner":"COO","action":"Human: confirm insurance coverage with broker"},{"id":"L15","area":"Breach notification (72h GDPR)","status":"partial","risk":"medium","note":"Privacy policy commits to notification. Internal incident runbook not productized.","owner":"CLO","action":"Document breach runbook + agency notification template"},{"id":"L16","area":"Isolation from BondPermit","status":"pass","risk":"low","note":"Separate tables, routes, legal pages — no commingling of permit advice with payment ops.","owner":"CTO"}],"legal_urls":{"terms":"https://glint.aurumflux.co/glint/terms","privacy":"https://glint.aurumflux.co/glint/privacy","client_auth":"https://glint.aurumflux.co/glint/client-auth","compliance":"https://glint.aurumflux.co/glint/legal/compliance"},"human_actions_required":["CLO: Review glint-terms.html + glint-privacy.html (counsel sign-off)","CTO: Register Shopify GDPR webhooks in Partner Dashboard","COO: Confirm cyber/E&O insurance for payment-system access product","CLO: Publish DPA template for EU/UK agency customers"]}