Terms · informed use · local-AI research

Version-bound informed-use record · MPL-2.0 rights preserved · public research preview

IntegrityLock Community Edition — Terms & Informed Use

This version-bound page explains the software license, research-preview boundaries, local-first posture, cryptographic meaning, local-AI integration, user responsibilities, and UVLM’s support and non-endorsement policies for IntegrityLock Community Edition v0.2.0-alpha.5.

The essentials

Open-source license

Covered software is distributed under Mozilla Public License 2.0. The included license—not this webpage—controls software rights and obligations.

Local-first operation

Ordinary use requires no UVLM account, activation, payment, model provider, or remote service. The optional HTTP interface is loopback-only.

Research preview

This alpha is provided for education, inspection, experimentation, and bounded local use. It is not a production certification.

Human authority remains

Hashes, signatures, manifests, and provenance records support inspection. They do not decide truth, authorship, consent, safety, legality, or release authority.

1. License hierarchy and legal effect

IntegrityLock’s software rights come from the exact license and notices distributed with the release. This webpage is a plain-language informed-use and website-governance summary. It does not replace, rewrite, or narrow the Mozilla Public License 2.0.

No extra software-use gate. Access to the source or binaries is not conditioned on a donation, account, activation, checkout, or click-through agreement. This page adds no field-of-use restriction and does not take away rights granted under MPL-2.0.
  • MPL-2.0 governs the covered source code and the obligations that arise when covered software is distributed.
  • Third-party components remain subject to their own listed licenses and notices.
  • UVLM names, logos, and product marks are not licensed merely because the code is open source. Forks must not imply UVLM sponsorship, certification, or official release status.
  • Website access, support channels, donation pages, and UVLM’s public representations remain separate from the software license.
  • The release’s included LICENSE, NOTICE, third-party inventory, SBOM, trademark policy, and source notices should be read together.
Exact source identity 90c6844f4de8a0d27f584a2adfdc4ebf693ae41b629b10f03a61c04f013fb736

2. Informed use

IntegrityLock is a local artifact-integrity, deterministic packaging, signing, package-vault, provenance-chain, and lineage-comparison toolkit. It helps people inspect declared relationships among bytes and records. It does not decide what those bytes mean.

What it can establish

Whether observed bytes match a declared hash; whether a manifest, sidecar, signature, archive, or chain verifies under the stated procedure; and how two closed indexes differ.

What it cannot establish

Truth, authorship, consent, lawful authority, malware absence, identity, credibility, moral fitness, production readiness, or whether a human account should be believed.

What the alpha means

Interfaces, packaging, documentation, and compatibility may change. Users should preserve exact versions, hashes, backups, and migration evidence rather than assuming future compatibility.

Credibility boundary. UVLM does not authorize or endorse using IntegrityLock to score whether a survivor, witness, employee, complainant, whistleblower, or source is truthful. A file hash can show byte identity; it cannot judge a person.
Hashes and signatures in plain language

A matching SHA-256 means the observed bytes match the declared digest under the stated calculation. It does not explain who created the content, whether the content is correct, or whether it should be acted upon.

A valid signature means a particular private key signed particular bytes. It does not by itself establish the key holder’s identity, role, permission, honesty, or legal authority.

3. Working beside a local AI model

IntegrityLock does not contain or invoke an AI model. It can sit beside Ollama, llama.cpp, LM Studio, a desktop model, a Python pipeline, or another user-selected local tool to preserve the exact materials used in an experiment.

Experiment sealing

Index and seal model manifests, quantization details, prompts, sources, adapters, settings, raw candidate outputs, reviewed outputs, metrics, and limitations.

Baseline comparison

Compare ordinary and governed runs to identify which model, prompt, source, adapter, configuration, output, or evaluation file changed.

Bounded tool use

A local orchestrator may call approved hashing, indexing, verification, chain, or lineage operations through the SDK, JSONL bridge, or loopback API. Tool capability is not authorization.

Model-output boundary. A model-generated response remains a candidate. Sealing, hashing, or signing it does not make it true, approved, safe, lawful, or suitable for publication.

Research claims about “improved performance”

IntegrityLock may improve system-level traceability, replayability, artifact completeness, rollback, and drift detection. It does not change model weights or automatically improve intelligence or benchmark accuracy.

  • Identify the exact model, version, quantization, and adapter.
  • Preserve prompts, sources, settings, seeds when available, and hardware.
  • Declare the baseline and the metric before interpreting results.
  • Report uncertainty, latency, resource cost, negative findings, and null results.
  • Do not rename better provenance or lower review burden as better intrinsic model intelligence.

4. Privacy, locality, vaults, and security

Locality

Ordinary operations read and write user-selected local paths. The release includes no UVLM account, activation, phone-home, analytics, remote storage, or model call.

Loopback is not isolation

The optional HTTP interface is loopback-only. A malicious process running with the same user permissions may still access local files or observe local traffic.

Vault custody

Optional .uvlock vaults use user-controlled passphrases. Losing a passphrase may make a vault unrecoverable. Vaults do not replace independent backups.

  • Do not place private keys, vault passphrases, credentials, customer records, or sensitive source material in public issue reports.
  • Maintain backups before sealing, encrypting, repairing, moving, or uninstalling software.
  • Use narrow allowed roots for SDK, JSONL, or API integrations.
  • Confirm that you have permission to process, copy, sign, encrypt, or publish every file you provide.
  • A local endpoint-security scan is not proof that software is free from malware.
Unsigned Windows packages. The Windows portable and installer candidate are unsigned. SmartScreen, antivirus, or organizational policy may warn, quarantine, delay, or block them. That limitation must remain visible wherever the downloads appear.

5. User responsibilities and non-endorsement

Open-source access does not transfer responsibility for the user’s files, systems, models, permissions, keys, decisions, backups, or legal obligations to UVLM.

  • Verify every download before extraction, installation, or execution.
  • Review the exact license, notices, SBOM, limitations, and security guidance.
  • Use synthetic, public, or properly authorized material for experiments.
  • Protect keys, passphrases, evidence, and sensitive data.
  • Do not represent a fork, modification, or result as an official UVLM release.
  • Do not claim certification, production approval, legal clearance, or malware absence.
  • Do not treat a successful technical verification as permission to publish or deploy.
  • Comply with applicable privacy, intellectual-property, sanctions, export, employment, contractual, and sector-specific obligations.
Warranty, support, and operational reliance

The included MPL-2.0 license contains the controlling software warranty and liability terms. UVLM does not provide an additional warranty, service-level agreement, continuous support promise, or fitness guarantee for this alpha unless a separate signed writing expressly says otherwise.

Community support, documentation, corrections, and future releases may be offered, changed, paused, or discontinued. Preserve the exact release you rely on.

6. Support, security reports, versions, and donations

Include the exact filename, SHA-256, operating system, interface, minimal synthetic reproduction, expected behavior, and observed behavior when reporting a defect. Remove secrets and personal data.

General questions Email a general inquiry
Technical support Email a support request
Version-bound guidance. This page applies to IntegrityLock Community Edition v0.2.0-alpha.5. A future release may change interfaces, packaging, dependencies, claims, or limitations. Verify the version and exact hashes before relying on any instruction.