All systemsIsland MapFamilyQuestsSchemasDataDownload package

Build specification

Security, Privacy, and Safety#

Default deny. Authorize before graph/vector retrieval and before Portal preview. Public/private/secret/personal are member-facing access levels; complete decisions also evaluate purpose, context, Role, policy, conflicts, time, state, and session assurance.

Personal is Source-and-Ally only and never grantable. Secret is not discoverable by search, counts, error timing, cached imagery, or federation. Credentials stay in a secrets system; files in encrypted object storage; the graph stores references and policy facts.

Models propose; named queries and Commands act. No generated Cypher, arbitrary CRUD, or model-authored receipt consequences. External content is untrusted context. Simulation credentials are structurally unable to reach real rails.

Threat tests: cross-shard privacy leak; secret Portal preview; prompt injection in ARG/web content; Actor grant escalation; idempotency replay; stale aggregate confirmation; presence stalking; inferred sensitive attribute; ledger/graph mismatch; child/minor access; malicious asset; denial reason leakage.