SAFETY / FAIL CLOSED

Some capabilities should not be automated

The service uses least privilege, rollback, and fail-closed decisions. Ambiguous scope stops before authorization expands.

Refuse

High-risk decisions

No medical, legal, or financial decisions; prohibited scraping, harassment, automatic payment, and irreversible automation are out of scope.

Local

Credentials and customer data

Passwords, API keys, and raw customer data never enter forms, Git, or delivery packages. Customers enter secrets on their own device.

Access

Customer-owned lawful routes

We support customer-owned official accounts or APIs and compatible endpoints the customer is authorized to use. We do not recommend specific VPNs, buy accounts, sell relay access, top up balances, or hold keys.

Redact

Repair diagnostics

Only customer-inspected JSON or Markdown from the local collector is accepted. Arbitrary files are rejected.

Approve

External actions

Sending, deleting, purchasing, publishing, refunds, and high-risk customers always require human approval.

Clean

Data retention

Nonfinancial customer data is selected for cleanup after 30 days. Cleanup defaults to dry-run and reports each candidate.