Confidential — Internal Use Only
Foundation Partner Handover

Known Technical Soft Spots

An honest accounting of where MarketMind AI stands today. This document captures the technical limitations a foundation partner should understand before engaging — what is real, what is aspirational, and what is being done about each gap. Soft spots are grouped by the layer they belong to: the intelligence platform being built, and the application surface that exists today.

Last updated: August 2026

How to read this

Each entry lists the current state, the practical impact, and the planned remediation. Status reflects where the work stands, not severity.

OpenPlannedIn Progress
Group 1

Foundation Build

The intelligence platform itself — the APIs, agent network, persistent memory, and compliance posture that the product is being built from. These soft spots describe what the underlying platform is missing before it can ship.

Platform StatusOpen

No live intelligence backend

Current state

The public site is a marketing surface. The intelligence APIs (/analyze, /generate-signal, /risk-assessment, /pattern-detection), the autonomous agent network, and the persistent memory layer are in the architecture and foundation phase — not yet serving production traffic. Any API request or agent activity shown in the UI is illustrative.

Practical impact

A visitor or design partner who attempts to call an endpoint today will not receive a real intelligence response. Demos and the sandbox are representative, not live.

Remediation

Ship the first 'wedge' — one Domain Pack, one endpoint — as a minimum viable product before opening general API access. All marketing copy already reflects this with future-tense 'building / architecting' framing.

CompliancePlanned

Not HIPAA-compliant; no BAA workflow

Current state

The platform is not HIPAA-compliant and has no Business Associate Agreement (BAA) workflow in place. GCP and Azure are HIPAA-eligible infrastructure providers, but MarketMind's own status is non-compliant — the two are distinct and should not be conflated.

Practical impact

The platform cannot onboard regulated protected health information (PHI). Health-adjacent marketing copy is limited to infrastructure eligibility, not MarketMind's own compliance status.

Remediation

Complete a BAA with each subprocessor and stand up the required administrative, physical, and technical safeguards before any PHI handling. Targeted post-seed alongside SOC 2 Type I.

Group 2

Application Build

This marketing site and web app — the surface partners and early visitors interact with today. These soft spots describe weaknesses in the current application layer, independent of the platform it advertises.

AuthenticationPlanned

Sign In is non-functional

Current state

The navbar Sign In button routes to the platform login flow, but there is no authenticated product experience behind it yet. Authenticated users land with nothing to do.

Practical impact

Early visitors who sign in find an empty state. No data is at risk — there is simply no product surface gated behind auth today.

Remediation

Gate real product features (API keys, sandbox, billing) behind authentication once the intelligence backend ships. Until then, the primary CTA remains 'Join Waitlist'.

Email DeliveryOpen

Early-access emails don't reach unregistered recipients

Current state

The platform email service reliably reaches registered app users. Waitlist confirmation emails sent to addresses that are not registered users may fail silently — the current plan does not support triggering emails to non-users.

Practical impact

A visitor who joins the waitlist may not receive a confirmation email, creating uncertainty about whether their signup was recorded (it is — the entry is persisted to the WaitlistEntry entity regardless).

Remediation

Migrate to a dedicated transactional email provider with a connected custom domain, or invite waitlist entries as registered users so confirmations deliver reliably.

Access ControlOpen

Confidential access gate is front-end only

Current state

The 'Confidential — Internal Use Only' gate on the cloud partnership briefs is a soft, client-side gate. There is no server-side validation before the page content is served.

Practical impact

Anyone with the direct URL can view content marked confidential. This is acceptable for partner handover (the URL is shared directly) but is not true access control.

Remediation

Move access control server-side — require an authenticated role or a single-use token before serving confidential page content. Do this before sharing any genuinely sensitive material.

The intent

None of these soft spots are hidden in the product experience — the marketing site already speaks in building and architecting terms. This document exists so the partner has the same clear picture we do, and so remediation can be tracked against a shared list.