An honest accounting of where MarketMind AI stands today. This document captures the technical limitations a foundation partner should understand before engaging — what is real, what is aspirational, and what is being done about each gap. Soft spots are grouped by the layer they belong to: the intelligence platform being built, and the application surface that exists today.
Last updated: August 2026
Each entry lists the current state, the practical impact, and the planned remediation. Status reflects where the work stands, not severity.
The intelligence platform itself — the APIs, agent network, persistent memory, and compliance posture that the product is being built from. These soft spots describe what the underlying platform is missing before it can ship.
The public site is a marketing surface. The intelligence APIs (/analyze, /generate-signal, /risk-assessment, /pattern-detection), the autonomous agent network, and the persistent memory layer are in the architecture and foundation phase — not yet serving production traffic. Any API request or agent activity shown in the UI is illustrative.
A visitor or design partner who attempts to call an endpoint today will not receive a real intelligence response. Demos and the sandbox are representative, not live.
Ship the first 'wedge' — one Domain Pack, one endpoint — as a minimum viable product before opening general API access. All marketing copy already reflects this with future-tense 'building / architecting' framing.
The platform is not HIPAA-compliant and has no Business Associate Agreement (BAA) workflow in place. GCP and Azure are HIPAA-eligible infrastructure providers, but MarketMind's own status is non-compliant — the two are distinct and should not be conflated.
The platform cannot onboard regulated protected health information (PHI). Health-adjacent marketing copy is limited to infrastructure eligibility, not MarketMind's own compliance status.
Complete a BAA with each subprocessor and stand up the required administrative, physical, and technical safeguards before any PHI handling. Targeted post-seed alongside SOC 2 Type I.
This marketing site and web app — the surface partners and early visitors interact with today. These soft spots describe weaknesses in the current application layer, independent of the platform it advertises.
The navbar Sign In button routes to the platform login flow, but there is no authenticated product experience behind it yet. Authenticated users land with nothing to do.
Early visitors who sign in find an empty state. No data is at risk — there is simply no product surface gated behind auth today.
Gate real product features (API keys, sandbox, billing) behind authentication once the intelligence backend ships. Until then, the primary CTA remains 'Join Waitlist'.
The platform email service reliably reaches registered app users. Waitlist confirmation emails sent to addresses that are not registered users may fail silently — the current plan does not support triggering emails to non-users.
A visitor who joins the waitlist may not receive a confirmation email, creating uncertainty about whether their signup was recorded (it is — the entry is persisted to the WaitlistEntry entity regardless).
Migrate to a dedicated transactional email provider with a connected custom domain, or invite waitlist entries as registered users so confirmations deliver reliably.
The 'Confidential — Internal Use Only' gate on the cloud partnership briefs is a soft, client-side gate. There is no server-side validation before the page content is served.
Anyone with the direct URL can view content marked confidential. This is acceptable for partner handover (the URL is shared directly) but is not true access control.
Move access control server-side — require an authenticated role or a single-use token before serving confidential page content. Do this before sharing any genuinely sensitive material.
None of these soft spots are hidden in the product experience — the marketing site already speaks in building and architecting terms. This document exists so the partner has the same clear picture we do, and so remediation can be tracked against a shared list.