Mockup Policy · Not Legal Advice

Privacy, Security & Engineering Disclaimer

This page is a design prototype for the safeguards, disclosures and product boundaries that would need formal legal, security, ethics and engineering review before a public launch.

Prototype rulePublic + synthetic data only.

Do not upload confidential, restricted, proprietary or employer-sensitive project information.

Proposed Security Principles

Security by architecture rather than promises alone.

1. Local-first project processingOriginal project documents should remain on the user's device by default. Future cloud processing should require explicit authorization and a defined data classification policy.
2. Clear data classificationPublic, internal/project and restricted data should be handled differently. Restricted classes should be technically blocked from cloud processing where required.
3. Sanitization before transmissionAny future sanitized-AI mode should perform sensitive-data detection, redaction/tokenization, metadata cleaning and verification locally before a payload leaves the device.
4. Least-privilege accessProduction authentication, authorization, project isolation, session controls and role permissions must ensure one user cannot access another user's project data.
5. Minimal telemetryApplication logs and analytics should never casually capture project content, credentials, restricted information or sensitive document text.
6. Reference provenanceEngineering references should preserve source, revision, effective date, retrieval date, validation status and official-source link.
7. Deterministic engineering calculationsCalculations should use validated formulas and structured criteria whenever possible. AI should assist with retrieval/interpretation, not replace authoritative engineering criteria.
8. Human professional reviewThe platform should never represent itself as the engineer of record. Outputs require qualified human review before use in engineering decisions.
9. Pre-launch adversarial testingAuthentication, authorization, file uploads, parser attacks, prompt injection, data leakage, backups, secure deletion, dependencies and incident response should be independently challenged before production use.
10. Employment, ethics and IP reviewCommercialization, use of employer-related information, public-document reuse, licensing, conflicts of interest and outside-employment boundaries should be reviewed and documented before launch.

Development Disclaimer

Not for production engineering use. v0.9.58 is a localhost development prototype. Calculator outputs, example project information, cost estimates, QA/QC checks, references and notices may be incomplete or intentionally synthetic. No result should be relied upon for design, bidding, construction, procurement, public safety or professional engineering decisions.

Future Privacy Modes

Conceptual product modes for later security review.

Local Only

Project stays on device

Local parsing, local calculations and local indexes. Project-document network transmission disabled.

Sanitized AI

Approved payload only

Original stays local; reviewed, sanitized data may be sent to an approved AI service under policy controls.

Cloud Project

Explicit organization approval

Encrypted synchronization only where the user or organization is authorized to store the project in a managed cloud environment.