Security / Data boundaries
Browser-first,
with boundaries you can inspect.
You choose the source set
The image workflow begins with files or a folder the user explicitly selects through the browser surface.
A browser-first image path
Supported transforms are designed to work inside the active browser session instead of relying on a per-image cloud queue.
Services stay distinguishable
Account, licence, billing, and optional diagnostics should remain separate from the product-image transformation path.
Data map
What belongs where
Selected source images
Active browser work session
Used for the transformation flow the user starts.
Generated output pack
User-initiated export
Created when the user asks Bloomcomp to package the results.
Recipe settings
Workspace settings
Configuration values, not the image pixels themselves.
Account and entitlement
Connected account service
Only relevant when sign-in or licensing is configured.
Read this precisely
Architecture is not certification.
This is the intended product boundary, not a claim of formal compliance, completed penetration testing, or an offline guarantee.
Production deployment should document every connected service, retention rule, telemetry choice, and network request.
A focused work surface
Keep image preparation close to the work.
Use the studio to select a source set, shape a recipe, and review the resulting pack before export.
