Use the receipt without surrendering judgment
Terms, informed use, and research boundaries
Use CECP to inspect a declared contract—not to authorize a life, decide a person, or replace accountable human judgment.
CECP evaluates one strict structured proposal against the fixed UVLM-CECP 1.1.0 contract and returns a replayable PASS, HOLD, or REJECT receipt. These terms explain how to interpret that receipt, how to protect people and data, and how to use the release responsibly in local-first research.
- Release 0.2.0-alpha.6
- Protocol UVLM-CECP 1.1.0
- MPL-2.0
- No model required
- No account or activation
- No persistent memory or training
- Not production ready
PASS is not approval. A CECP result concerns the submitted object, declared evidence bindings, and stated observation time. It does not prove external facts or grant truth, legal, ethical, political, regulatory, cultural, moral, scientific, clinical, or operational authority.
What you should understand before use
These six boundaries are the center of the release posture. A result remains bounded even when every technical control passes.
CECP evaluates what you submit
It checks a structured proposal and declared evidence relationships. It does not investigate the world beyond that submitted object.
Bindings are not facts
A digest can bind bytes to a declaration. It cannot establish that an outside document, event, witness, authority, or consent process is genuine.
The decision remains human
CECP may organize a review. It cannot make a lawful, ethical, clinical, employment, benefits, detention, punishment, or essential-service decision.
Results are time-bound
A receipt reflects the stated observation time and supplied context. Changed facts, evidence, rights, or conditions require a new assessment.
This is an alpha preview
It is unsigned, not production ready, and not a substitute for legal review, professional assurance, accessibility certification, or incident response.
A receipt cannot make itself final
Every receipt preserves authority_effect: NONE. A later workflow must not silently reinterpret it as permission or truth.
How to interpret PASS, HOLD, and REJECT
The three results are ordered contract states. None is a rating of a person, culture, ideology, or testimony.
PASS
The submitted proposal satisfied the fixed contract at the declared observation time. PASS is not endorsement, permission, compliance, legitimacy, or fact verification.
HOLD
Required evidence or a bounded criterion remains unresolved, including unknown codes or incomplete rights, burden, consent, authorization, appeal, rollback, or revocation.
REJECT
The declared proposal contains an effect or means prohibited by rights-floor-v1. The result concerns the proposal—not a person’s worth or credibility.
People are not contract objects
Do not use CECP to turn vulnerable people, disputed testimony, identity, or social status into machine-scored eligibility.
- Scoring survivor, witness, employee, complainant, or source credibility.
- Scoring human worth, ideology, religion, culture, trauma, diagnosis, dangerousness, or deservingness.
- Automating employment, benefits, housing, education, healthcare, detention, punishment, policing, or access to essential services.
- Using a PASS to bypass consent, due process, appeal, professional review, or accountable authority.
- Use synthetic, public, de-identified, or properly authorized material.
- Review effects on affected people before treating a technical result as useful.
- Preserve disagreement, correction, appeal, and revocation routes.
- Keep a competent human responsible for the final real-world decision.
Evidence, facts, and user responsibility
CECP can validate structure, scope declarations, references, and digests. The user remains responsible for the truthfulness, permissions, relevance, and lawful handling of submitted material.
Use material you may lawfully process
Do not submit secrets, private keys, unauthorized records, confidential employer or client material, or personal evidence merely because the software is local.
Declare uncertainty honestly
Unknown, disputed, incomplete, expired, revoked, or unverified evidence should remain visibly unresolved rather than being described as satisfied.
Reassess changed conditions
Do not reuse an old receipt after facts, permissions, affected parties, burdens, means, effects, or authorities materially change.
Hash boundary. A matching SHA-256 establishes byte identity with the expected artifact. It does not prove that the content is true, safe, lawful, complete, ethical, current, or fit for a particular purpose.
Local-first privacy and device security
The CECP core, CLI, SDK, and loopback browser are designed for local operation. Local use reduces one class of transmission risk; it does not make the device or surrounding software private by itself.
- No model or provider route.
- No account, activation, storefront, payment, or donation gate.
- No analytics, update check, persistent memory, or model training.
- Packaged browser assets and loopback-only local interface.
- New-only output paths; CECP does not overwrite source inputs.
- Your operating system, browser, backup tools, antivirus, sync software, and other applications have separate behavior.
- Protect the device, account, output folder, and backups appropriate to the sensitivity of the material.
- Unsigned Windows artifacts may be warned against or blocked; do not disable organizational security policy merely to run them.
- Report unexpected transmission, non-loopback binding, overwrite, deletion, or secret exposure.
Using CECP beside a local AI model
CECP does not include or call a model. Researchers may place it beside a user-selected local model as a separate deterministic review step.
Model output remains a candidate. An AI may help draft a proposal, but it cannot grant itself evidence, consent, authority, or a favorable result. The adapter should preserve the model identity, prompt, source set, configuration, raw candidate, human edits, and CECP receipt.
Performance claims must be measured. CECP may improve system-level outcomes such as review consistency, unsupported-claim visibility, replayability, or correction discipline. Do not describe those gains as improved model weights or general intelligence unless separately measured against a declared baseline.
No silent memory or training. A CECP receipt is not permission to retain personal material, write persistent AI memory, train a model, publish a result, or operationalize a proposal.
Open-source rights and responsibilities
CECP Community Edition source code is distributed under MPL-2.0. Third-party materials remain under their listed licenses and notices.
Study, test, fork, and contribute
Use the source, schemas, fixtures, and tests to understand or improve the tool within the license and applicable third-party terms.
Do not obscure modifications
Keep required notices, distinguish your modified version, and preserve correction and vulnerability-reporting routes appropriate to your fork.
A fork is not an official UVLM release
Open-source rights do not authorize false endorsement, official-release claims, certification claims, or misuse of UVLM names and marks.
These informed-use boundaries do not replace the complete MPL-2.0 text, third-party licenses, trademark policy, applicable law, or your organization’s own governance requirements.
Support, corrections, and security
Use synthetic or minimized examples. Do not send passwords, private keys, personal evidence, vault secrets, exploit details, or confidential source through ordinary email.
General support
Installation, verification, documentation, and ordinary product questions.
Email CECP supportPublic correction
Report an inaccurate public claim, broken link, stale instruction, or documentation defect.
Request a correctionSensitive security issue
Begin with a minimal notice. Ask for a protected route before sending sensitive reproduction details.
Start a security report