Trust & evaluation

Evaluate PAVONA
on your own work.

Start by giving PAVONA one useful job. You choose the data it can see, the tools it can use and the result you expect. Review the work before you give it more to do.

Discuss an evaluation Inspect the release

Who publishes this

PAVONA is published by BEM Bio-Engineered Mechanics. Business and privacy questions go to outreach@priest.locker. Product support stays at support@priest.locker. Read the full terms on the Terms page and how data is handled on the Privacy page.

Your data

Where your data goes

Local models

Inference runs on the computer hosting the model. Conversations are stored on your disk. Connected tools can still use the network, so running the model locally does not make every action offline.

Code: dashboard/convo_store.py

Cloud models & tools

The providers and tools you configure receive the data needed for their requests. Review the destination, permissions and provider terms before using company information. Provider charges are separate.

Code: priest_core/gateway/routing.py, priest_core/privacy/destinations.py

Downloads & updates

Setup, model downloads and release checks use the network. The app checks for releases every six hours while open; downloading and installing an update requires confirmation.

Code: dashboard/version.py, dashboard/priest-panels.js

Support reports

Review the report before sending it. Remove customer information, credentials and sensitive attachments. Reports sent by email pass through your mail provider and the support mailbox.

Code: dashboard/priest.html

Listening room

The home page names a track before anything loads. Pressing Play connects to Spotify to play it; Spotify can then see your IP address, the same as any embedded player. Closing the player is remembered on your browser.

Code: site/music-dock.js

Read the data terms · Understand tool permissions

Plan a pilot

Choose a workflow and agree how to measure it.

01 / Define

Choose the work

Bring a development task, a repeatable support problem or a security review of systems you own or are authorised to assess. Agree the scope and a named decision maker.

02 / Evaluate

Keep the evidence

Use a separate evaluation workspace and non-sensitive sample data. Record setup time, completion quality, tool approvals, model cost and the recovery steps when something fails.

03 / Decide

Review the results

Review the output and unresolved issues together. Confirm deployment requirements, licensing, support arrangements and ownership before a wider rollout.

Prepare an evaluation

Create a
pilot brief.

Choose a workflow and a data boundary. You get an evaluation plan that lists the evidence to collect and ends with a decision.

The planner runs in this page. Your entries are not submitted or saved. Download your brief to keep it. The email link prepares a draft that you review and send yourself.

Download the blank brief

Security

Testing with a defined scope

VERIDITAS is PAVONA's security workbench. To evaluate it, run an authorised test, check that its findings can be reproduced and keep evidence of the fixes. Security testing needs an agreed target, permission from its owner and a clear stop condition.

Verify the software you receive

The release page publishes version information and checksums. Check the downloaded file against the published SHA-256 before running it. A checksum verifies the file against that published value. It is not a code-signing certificate or an independent security audit.

Release files & checksums

Report a vulnerability privately

Email support@priest.locker with “Security report” in the subject. Include the affected version, expected and actual behaviour, and minimal reproduction steps. Omit credentials and personal data. Support is best-effort, and no response time is promised.

Before production

Check your production requirements.

PAVONA is in beta. Enterprise evaluation should confirm identity integration, tenant isolation, data handling, deployment support and recovery against your requirements. Record any gaps before making a deployment decision.

Current assurance status

No independent penetration-test result, compliance certification, production SLA or code-signing certificate is claimed here. OpenAI Daybreak partnership and specialised model access are not claimed. Those require separate approval and evidence.

OpenAI's published access requirements

Discuss an evaluation

Current release status

The release page lists the current public version and verified download hashes. Read the release status for validation scope and work still in development.