> ## Documentation Index
> Fetch the complete documentation index at: https://evalgate.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Production adoption

> A staged, evidence-based path for piloting EvalGate without assuming unverified availability or compliance guarantees.

# Production adoption

EvalGate is currently offered as a controlled beta. This guide helps a team
adopt the verified parts of the platform without treating a beta or experimental
surface as a general-availability promise.

<Warning>
  EvalGate does not publish a default uptime SLA, SOC 2 certification, universal
  data-residency commitment, or guaranteed support-response time today.
  Governance templates are product controls, not certifications. Any negotiated
  enterprise term must appear in the customer's signed agreement.
</Warning>

## Stage the rollout

| Stage                      | Scope                                                       | Exit evidence                                                                             |
| -------------------------- | ----------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Repository setup           | One repository, non-production organization, scoped API key | Correct repository/branch/root, key owner, revocation test, no cross-org access           |
| Deterministic gate         | One existing test command and reviewed baseline             | Passing baseline, deliberate regression failure, CI artifact tied to an exact commit      |
| Trace and evaluation pilot | One bounded staging workflow                                | Successful and failed traces, reviewed cases, explicit provider/parser/budget failures    |
| Runtime controls           | One governed model or agent action path                     | Allowed and denied policy tests, approval proof, policy snapshot, audit evidence          |
| Release use                | One non-critical release decision with a human owner        | Rollback plan, feature-status review, incident path, signed or retained report evidence   |
| Broader adoption           | Additional teams and repositories                           | Tenant/access review, data-flow review, load evidence, named owners, commercial agreement |

## Review the public evidence

Before each expansion, review:

* [Feature status](/docs/platform/feature-status) for the authoritative maturity label;
* [Current-behavior manuals](/docs/platform/feature-manuals) for permissions, limits,
  failure states, and recovery paths;
* [Security and data handling](https://www.evalgate.com/security) for implemented
  controls and explicit certification boundaries;
* [Model providers and BYOK](/docs/platform/model-providers-byok) for the separate
  provider billing, retention, training, and residency contract; and
* [Rate limits](/docs/platform/rate-limits) for client backoff and usage behavior.

Source tests, routes, or UI screens are evidence inputs, not availability by
themselves. When a public document and the runtime disagree, use the more
restrictive behavior and report the mismatch.

## Define ownership before a release gate

Assign people or teams for:

* API-key issuance, scope review, and revocation;
* repository and baseline approval;
* provider credentials, data policy, and spend limits;
* evaluator calibration and failure triage;
* CI override and production rollback decisions; and
* incident communication and evidence retention.

EvalGate records decisions and evidence; it does not replace your change
management, incident response, or provider contract.

## Large organizations

The four public plans remain uncapped at the published overage rate. Organizations
with more than 5 million monthly results, multiple business units, procurement or
invoicing requirements, or negotiated security and support terms should use the
Strategic Enterprise path on the [pricing page](https://www.evalgate.com/pricing).

Strategic Enterprise is a commercial review path, not a promise that every
requested control, certification, region, SSO configuration, SLA, or support tier
already exists. The agreed scope, volume schedule, rollout plan, and obligations
must be documented before adoption.

## Report a gap

Send security and production-adoption questions to `team@evalgate.com`. Include
the organization, surface, exact route or command, timestamp, request ID, and the
expected versus observed result. Do not include API keys or provider secrets.
