PAILEvidence Runtime
Security boundary

Expose the contract. Protect the runtime.

01

Public Worker, private evidence runtime

The Cloudflare Worker serves pages, authentication, quotas, tenant metadata, and bounded evaluators. Uploaded file bodies are forwarded to a separately operated PAIL runtime. Only a bounded evidence packet can proceed to optional generation. Private grammar rules, ranking policy, acoustic research, memory state, secrets, and customer data are not included in this repository.

02

Implemented controls

ControlCurrent behavior
Authentication15-minute email links, Secure HttpOnly session cookies, and hashed API keys.
Tenant isolationCorpus ownership is checked in Cloudflare and again in the private gateway.
Trial boundsTen protected queries per account, 1-5 files, 5 MB total, and a 24-hour corpus lifetime.
Generation gateConflict, missing evidence, failed guard state, and demo packets never reach Workers AI.
StorageRaw files bypass D1; query history stores a digest and bounded summary, not raw query text.
Browser policySame-origin CSP, frame denial, MIME protection, restricted permissions, HSTS, and no third-party fonts.
Static analysisRepository workflows run contract tests and CodeQL on the public JavaScript/Python surface.
03

Bounded data path

Browser files pass transiently through Cloudflare to an authenticated private gateway. The gateway writes an isolated per-corpus PAIL store, removes the original upload copy after ingestion, enforces tenant ownership, and expires the corpus within 24 hours. The browser can request immediate corpus deletion.

Use only synthetic, public, or properly sanitized material. Do not upload card data, credentials, patient data, live customer records, or confidential company information to the public trial.

04

No certification claim

These controls are code-reviewed and regression-tested, but the service has no independent penetration-test report, SOC 2 report, production SLA, or customer security acceptance yet. A real deployment needs managed secrets, customer identity, monitoring, backup and restore, incident response, and independent testing.

05

Coordinated disclosure

Start a private contact request with SECURITY DISCLOSURE REQUEST. Do not include exploit details or secrets in the first message. Automated scanners can use security.txt.