The privacy boundary is a designed artifact. Identity and event data are kept in separate domains. The buyer receives cohort-shaped output only. Reidentification and singling-out remain residual risks and are managed, not eliminated.
Inputs enter via opaque tokens issued by a documented surface. Identity-bound fields are filtered at the edge or routed to a separate identity domain.
Identity and event data do not co-reside. Cross-domain joins are a privileged operation, logged and budgeted.
Outbound contracts emit aggregates with provenance, retention, and revocation metadata. Raw events and per-user rows do not exit.
Cohorts below the minimum count are suppressed at the boundary. Sizes are rounded to defeat near-singling-out.
Residual risks are named, not hidden. Mitigations are documented in the threat model and reviewed on a quarterly cadence.
Revocation propagates to ingestion and cohort construction within the documented window. Revoked tokens are not silently reactivated.