Terms · informed use · local-AI research
Version-bound informed-use record · MPL-2.0 rights preserved · public research preview
IntegrityLock Community Edition — Terms & Informed Use
This version-bound page explains the software license, research-preview boundaries, local-first posture, cryptographic meaning, local-AI integration, user responsibilities, and UVLM’s support and non-endorsement policies for IntegrityLock Community Edition v0.2.0-alpha.5.
The essentials
Open-source license
Covered software is distributed under Mozilla Public License 2.0. The included license—not this webpage—controls software rights and obligations.
Local-first operation
Ordinary use requires no UVLM account, activation, payment, model provider, or remote service. The optional HTTP interface is loopback-only.
Research preview
This alpha is provided for education, inspection, experimentation, and bounded local use. It is not a production certification.
Human authority remains
Hashes, signatures, manifests, and provenance records support inspection. They do not decide truth, authorship, consent, safety, legality, or release authority.
1. License hierarchy and legal effect
IntegrityLock’s software rights come from the exact license and notices distributed with the release. This webpage is a plain-language informed-use and website-governance summary. It does not replace, rewrite, or narrow the Mozilla Public License 2.0.
- MPL-2.0 governs the covered source code and the obligations that arise when covered software is distributed.
- Third-party components remain subject to their own listed licenses and notices.
- UVLM names, logos, and product marks are not licensed merely because the code is open source. Forks must not imply UVLM sponsorship, certification, or official release status.
- Website access, support channels, donation pages, and UVLM’s public representations remain separate from the software license.
-
The release’s included
LICENSE,NOTICE, third-party inventory, SBOM, trademark policy, and source notices should be read together.
2. Informed use
IntegrityLock is a local artifact-integrity, deterministic packaging, signing, package-vault, provenance-chain, and lineage-comparison toolkit. It helps people inspect declared relationships among bytes and records. It does not decide what those bytes mean.
What it can establish
Whether observed bytes match a declared hash; whether a manifest, sidecar, signature, archive, or chain verifies under the stated procedure; and how two closed indexes differ.
What it cannot establish
Truth, authorship, consent, lawful authority, malware absence, identity, credibility, moral fitness, production readiness, or whether a human account should be believed.
What the alpha means
Interfaces, packaging, documentation, and compatibility may change. Users should preserve exact versions, hashes, backups, and migration evidence rather than assuming future compatibility.
Hashes and signatures in plain language
A matching SHA-256 means the observed bytes match the declared digest under the stated calculation. It does not explain who created the content, whether the content is correct, or whether it should be acted upon.
A valid signature means a particular private key signed particular bytes. It does not by itself establish the key holder’s identity, role, permission, honesty, or legal authority.
3. Working beside a local AI model
IntegrityLock does not contain or invoke an AI model. It can sit beside Ollama, llama.cpp, LM Studio, a desktop model, a Python pipeline, or another user-selected local tool to preserve the exact materials used in an experiment.
Experiment sealing
Index and seal model manifests, quantization details, prompts, sources, adapters, settings, raw candidate outputs, reviewed outputs, metrics, and limitations.
Baseline comparison
Compare ordinary and governed runs to identify which model, prompt, source, adapter, configuration, output, or evaluation file changed.
Bounded tool use
A local orchestrator may call approved hashing, indexing, verification, chain, or lineage operations through the SDK, JSONL bridge, or loopback API. Tool capability is not authorization.
Research claims about “improved performance”
IntegrityLock may improve system-level traceability, replayability, artifact completeness, rollback, and drift detection. It does not change model weights or automatically improve intelligence or benchmark accuracy.
- Identify the exact model, version, quantization, and adapter.
- Preserve prompts, sources, settings, seeds when available, and hardware.
- Declare the baseline and the metric before interpreting results.
- Report uncertainty, latency, resource cost, negative findings, and null results.
- Do not rename better provenance or lower review burden as better intrinsic model intelligence.
4. Privacy, locality, vaults, and security
Locality
Ordinary operations read and write user-selected local paths. The release includes no UVLM account, activation, phone-home, analytics, remote storage, or model call.
Loopback is not isolation
The optional HTTP interface is loopback-only. A malicious process running with the same user permissions may still access local files or observe local traffic.
Vault custody
Optional .uvlock vaults use user-controlled
passphrases. Losing a passphrase may make a vault unrecoverable.
Vaults do not replace independent backups.
- Do not place private keys, vault passphrases, credentials, customer records, or sensitive source material in public issue reports.
- Maintain backups before sealing, encrypting, repairing, moving, or uninstalling software.
- Use narrow allowed roots for SDK, JSONL, or API integrations.
- Confirm that you have permission to process, copy, sign, encrypt, or publish every file you provide.
- A local endpoint-security scan is not proof that software is free from malware.
5. User responsibilities and non-endorsement
Open-source access does not transfer responsibility for the user’s files, systems, models, permissions, keys, decisions, backups, or legal obligations to UVLM.
- Verify every download before extraction, installation, or execution.
- Review the exact license, notices, SBOM, limitations, and security guidance.
- Use synthetic, public, or properly authorized material for experiments.
- Protect keys, passphrases, evidence, and sensitive data.
- Do not represent a fork, modification, or result as an official UVLM release.
- Do not claim certification, production approval, legal clearance, or malware absence.
- Do not treat a successful technical verification as permission to publish or deploy.
- Comply with applicable privacy, intellectual-property, sanctions, export, employment, contractual, and sector-specific obligations.
Warranty, support, and operational reliance
The included MPL-2.0 license contains the controlling software warranty and liability terms. UVLM does not provide an additional warranty, service-level agreement, continuous support promise, or fitness guarantee for this alpha unless a separate signed writing expressly says otherwise.
Community support, documentation, corrections, and future releases may be offered, changed, paused, or discontinued. Preserve the exact release you rely on.
6. Support, security reports, versions, and donations
Include the exact filename, SHA-256, operating system, interface, minimal synthetic reproduction, expected behavior, and observed behavior when reporting a defect. Remove secrets and personal data.