Public open-source research preview · Informed-use boundary

Use the receipt without surrendering judgment

Terms, informed use, and research boundaries

Use CECP to inspect a declared contract—not to authorize a life, decide a person, or replace accountable human judgment.

CECP evaluates one strict structured proposal against the fixed UVLM-CECP 1.1.0 contract and returns a replayable PASS, HOLD, or REJECT receipt. These terms explain how to interpret that receipt, how to protect people and data, and how to use the release responsibly in local-first research.

  • Release 0.2.0-alpha.6
  • Protocol UVLM-CECP 1.1.0
  • MPL-2.0
  • No model required
  • No account or activation
  • No persistent memory or training
  • Not production ready

PASS is not approval. A CECP result concerns the submitted object, declared evidence bindings, and stated observation time. It does not prove external facts or grant truth, legal, ethical, political, regulatory, cultural, moral, scientific, clinical, or operational authority.

What you should understand before use

These six boundaries are the center of the release posture. A result remains bounded even when every technical control passes.

Contract scope

CECP evaluates what you submit

It checks a structured proposal and declared evidence relationships. It does not investigate the world beyond that submitted object.

Evidence scope

Bindings are not facts

A digest can bind bytes to a declaration. It cannot establish that an outside document, event, witness, authority, or consent process is genuine.

Human authority

The decision remains human

CECP may organize a review. It cannot make a lawful, ethical, clinical, employment, benefits, detention, punishment, or essential-service decision.

Temporal scope

Results are time-bound

A receipt reflects the stated observation time and supplied context. Changed facts, evidence, rights, or conditions require a new assessment.

Software scope

This is an alpha preview

It is unsigned, not production ready, and not a substitute for legal review, professional assurance, accessibility certification, or incident response.

No authority effect

A receipt cannot make itself final

Every receipt preserves authority_effect: NONE. A later workflow must not silently reinterpret it as permission or truth.

How to interpret PASS, HOLD, and REJECT

The three results are ordered contract states. None is a rating of a person, culture, ideology, or testimony.

PASS

The submitted proposal satisfied the fixed contract at the declared observation time. PASS is not endorsement, permission, compliance, legitimacy, or fact verification.

HOLD

Required evidence or a bounded criterion remains unresolved, including unknown codes or incomplete rights, burden, consent, authorization, appeal, rollback, or revocation.

REJECT

The declared proposal contains an effect or means prohibited by rights-floor-v1. The result concerns the proposal—not a person’s worth or credibility.

People are not contract objects

Do not use CECP to turn vulnerable people, disputed testimony, identity, or social status into machine-scored eligibility.

Prohibited decision uses
  • Scoring survivor, witness, employee, complainant, or source credibility.
  • Scoring human worth, ideology, religion, culture, trauma, diagnosis, dangerousness, or deservingness.
  • Automating employment, benefits, housing, education, healthcare, detention, punishment, policing, or access to essential services.
  • Using a PASS to bypass consent, due process, appeal, professional review, or accountable authority.
Appropriate research posture
  • Use synthetic, public, de-identified, or properly authorized material.
  • Review effects on affected people before treating a technical result as useful.
  • Preserve disagreement, correction, appeal, and revocation routes.
  • Keep a competent human responsible for the final real-world decision.

Evidence, facts, and user responsibility

CECP can validate structure, scope declarations, references, and digests. The user remains responsible for the truthfulness, permissions, relevance, and lawful handling of submitted material.

Before assessment

Use material you may lawfully process

Do not submit secrets, private keys, unauthorized records, confidential employer or client material, or personal evidence merely because the software is local.

During assessment

Declare uncertainty honestly

Unknown, disputed, incomplete, expired, revoked, or unverified evidence should remain visibly unresolved rather than being described as satisfied.

After assessment

Reassess changed conditions

Do not reuse an old receipt after facts, permissions, affected parties, burdens, means, effects, or authorities materially change.

Hash boundary. A matching SHA-256 establishes byte identity with the expected artifact. It does not prove that the content is true, safe, lawful, complete, ethical, current, or fit for a particular purpose.

Local-first privacy and device security

The CECP core, CLI, SDK, and loopback browser are designed for local operation. Local use reduces one class of transmission risk; it does not make the device or surrounding software private by itself.

CECP core posture
  • No model or provider route.
  • No account, activation, storefront, payment, or donation gate.
  • No analytics, update check, persistent memory, or model training.
  • Packaged browser assets and loopback-only local interface.
  • New-only output paths; CECP does not overwrite source inputs.
Your environment
  • Your operating system, browser, backup tools, antivirus, sync software, and other applications have separate behavior.
  • Protect the device, account, output folder, and backups appropriate to the sensitivity of the material.
  • Unsigned Windows artifacts may be warned against or blocked; do not disable organizational security policy merely to run them.
  • Report unexpected transmission, non-loopback binding, overwrite, deletion, or secret exposure.

Using CECP beside a local AI model

CECP does not include or call a model. Researchers may place it beside a user-selected local model as a separate deterministic review step.

Local model produces a candidate
Human checks sources and scope
Adapter creates strict CECP proposal
CECP returns PASS, HOLD, or REJECT
Human decides, repairs, or stops

Model output remains a candidate. An AI may help draft a proposal, but it cannot grant itself evidence, consent, authority, or a favorable result. The adapter should preserve the model identity, prompt, source set, configuration, raw candidate, human edits, and CECP receipt.

Performance claims must be measured. CECP may improve system-level outcomes such as review consistency, unsupported-claim visibility, replayability, or correction discipline. Do not describe those gains as improved model weights or general intelligence unless separately measured against a declared baseline.

No silent memory or training. A CECP receipt is not permission to retain personal material, write persistent AI memory, train a model, publish a result, or operationalize a proposal.

Open-source rights and responsibilities

CECP Community Edition source code is distributed under MPL-2.0. Third-party materials remain under their listed licenses and notices.

Inspect and improve

Study, test, fork, and contribute

Use the source, schemas, fixtures, and tests to understand or improve the tool within the license and applicable third-party terms.

Preserve lineage

Do not obscure modifications

Keep required notices, distinguish your modified version, and preserve correction and vulnerability-reporting routes appropriate to your fork.

Trademark boundary

A fork is not an official UVLM release

Open-source rights do not authorize false endorsement, official-release claims, certification claims, or misuse of UVLM names and marks.

These informed-use boundaries do not replace the complete MPL-2.0 text, third-party licenses, trademark policy, applicable law, or your organization’s own governance requirements.

Support, corrections, and security

Use synthetic or minimized examples. Do not send passwords, private keys, personal evidence, vault secrets, exploit details, or confidential source through ordinary email.

General support

Installation, verification, documentation, and ordinary product questions.

Email CECP support

Public correction

Report an inaccurate public claim, broken link, stale instruction, or documentation defect.

Request a correction

Sensitive security issue

Begin with a minimal notice. Ask for a protected route before sending sensitive reproduction details.

Start a security report