LivePublic rights, policies, records, and challenge routesExperimentalDesigned and synthetically tested controlsPlannedProduction operation and independent review

Trust Center

Trust begins with visible limits.

A documented control is not a deployed control. A passing test is not independent certification. A public promise must remain challengeable.

This page organizes the accepted public rights, privacy boundary, security posture, authority separations, provider and connector status, funding doctrine, open gates, and correction paths. It is a read-only explanation of repository records, not a second policy system.

The site does not process production health data and does not claim production security, privacy, accessibility, clinical, legal, financial, provider, or institutional certification.

Evidence by domain

What is protected, proven, and still open.

Each domain links to its upstream repository authority and carries the same controlled status vocabulary used across the public site.

Live

Player rights and the Promise

The public rights floor protects personal value, meaningful refusal, privacy, access control, provenance, correction, export, deletion where possible, and non-punitive return.

A website page, metric, sponsor, provider, model, or implementation cannot silently amend the frozen Promise or Seven Laws.

Read the Product Constitution (opens in a new tab)
Live

Public software, private personal data

The repository, website, tests, fixtures, previews, logs, and contributor workflows permit public information and explicitly synthetic evidence only.

No production health data, private signup record, credential, protected report, contract, or private financial source belongs in public project systems.

Read the publication boundary (opens in a new tab)
Experimental

Security and privacy controls

Sprint 5 established public architecture, control objectives, residual-risk registers, synthetic abuse cases, and founding-steward design table exercises.

Documented or synthetically exercised controls are not deployed controls, operational verification, penetration testing, or independent security certification.

Inspect the security architecture (opens in a new tab)
Experimental

Authority remains separated

Chronicle truth, permission truth, identity, execution, receipts, protected audit, product state, AI proposals, providers, and public institutional records remain distinct domains.

A successful model response, tool call, build, provider claim, security control, or website label cannot create permission, Chronicle truth, clinical authority, or governance legitimacy.

Inspect current authority boundaries (opens in a new tab)
Planned

Providers and connectors

Providers, EHRs, laboratories, pharmacies, devices, standards, and institutions may become valuable sources, destinations, and collaborators through later bounded adapters.

No provider, EHR, connector, clinical workflow, institutional access path, recommendation, ranking, or preferred integration is live.

Read the consumer-first decision (opens in a new tab)
Live

Funding and sponsorship doctrine

Accepted public rules prevent money, credits, infrastructure, distribution, or market access from purchasing data, product authority, favorable findings, provider placement, connector priority, or governance power.

No operating treasury, legal entity, payment rail, donation runtime, tax claim, accepted sponsor, provider relationship, or independent financial review is established.

Inspect the funding doctrine (opens in a new tab)
Live

Correction, challenge, and revalidation

Public issues and governed records provide the current public-safe path to challenge assumptions, evidence, incentives, architecture, policy, authority, and public claims.

The project has no permanent tribunal or ombuds office. Protected health, security, legal, conduct, personnel, or third-party evidence must use the appropriate private route.

Read the Institutional Immune System (opens in a new tab)
Planned

Independent and affected-user review

Independent security, privacy, accessibility, AI-safety, clinical, interoperability, legal, financial, operational, and affected-user review remains an explicit gate.

Founding-steward acceptance and passing CI are accountable internal evidence, not independent certification or production approval.

Review the open project gates (opens in a new tab)

Challenge and correction

Use the route that matches the information.

A public concern does not need a complete replacement solution. It does need an honest description, public-safe evidence, uncertainty, affected groups, and the narrowest useful correction or containment path available.

PlannedOpen operational and review gates

No public page closes these gates.

  • No production health-data, identity, permission-enforcement, provider, connector, clinical, research, payment, or private-AI runtime is authorized.
  • No representative accessibility review, accessibility certification, independent penetration test, or production security verification is complete.
  • No dedicated disclosure address, ombuds office, permanent tribunal, or independent institutional review body is established.
  • No public page may publish protected vulnerability details, private reports, credentials, personal data, contracts, negotiations, or raw financial records.