Authoritative documentation · English
Security boundaries
Book data is encrypted at rest. Small secrets belong in the operating-system protected store; provider keys, vault keys, signing keys, and license issuer secrets must never enter a webview, package, log, diagnostic archive, or source repository.
Publication is fail-closed
A release requires validated knowledge, admissible evidence, pinned retrieval policy, verified model and tokenizer artifacts, passing evaluation evidence, compatibility facts, and signatures. A missing gate blocks publication; it never produces a placeholder success.
Hosted-service boundary
The account, billing, download, licensing, and relay control plane stores no Book sources, extracted text, knowledge, indexes, conversations, or release bodies. Provider relay bodies are transient in protected memory and must not appear in logs, traces, metrics, analytics, or crash reports.
Offline limits
Device-bound licenses can be verified offline, but disconnected revocation cannot be immediate and Harnesser cannot recover a lost local vault key. Keep encrypted backups and recovery credentials under separate operator control.