Security
This informational template is pending operator and legal review. It describes current website boundaries, not an approved security policy, audit, certification, or service guarantee.
1. What is running here
This is a presentation website with local interactive previews. There is no live camera integration, AI inference service, login, account connection, or remote tool execution. The simulated terminal, browser, files, calls, and attachments do not execute commands, browse external sites, access your filesystem, or record media.
2. Local does not mean risk-free
Demo input remains in page memory and is reset on reload. The language preference is stored separately in a cookie. Ordinary page delivery still uses a network, and your browser, extensions, device, and hosting environment are separate security boundaries. Keep your browser updated and avoid entering secrets or personal data in previews. This page does not promise confidentiality, uninterrupted availability, or the absence of vulnerabilities.
Read the privacy draft3. Product concepts are not deployed controls
Architecture diagrams and product descriptions illustrate possible deployments. Isolation, access control, encryption coverage, retention, updates, monitoring, and recovery must be specified and tested for each real deployment. References to human approval or local-first operation are not evidence that a connected service has been secured. No compliance certification or independent security assessment is asserted here.
4. Reporting a suspected issue
A verified security reporting channel has not yet been published on this site. If you already have an independently verified operator contact, ask for a private reporting channel before sharing sensitive evidence. Otherwise, retain a minimal, redacted report until a verified channel is available. The demo is not a reporting form and does not deliver messages to the operator.
Include the affected page, time observed, browser version, minimal reproduction steps, and potential impact. Remove credentials and personal data from screenshots and logs. Do not access other people’s data, disrupt availability, or continue testing after unintended access. This guidance does not authorize intrusive testing, establish a bounty or safe-harbor program, or promise a response or remediation deadline.
5. Before a live release
The operator must verify hosting controls, define incident ownership, publish a monitored reporting channel, and review the actual data flows before offering connected functionality. Review this information when integrations or deployment practices change.