Core Features Security & Privacy 1.4.0
Cross-cutting runtime, Local AI, Blocks, audit, and Inspector safety boundaries.
Security model
Signals → Policy → optional Local AI ranker → Intent → Validator → Guardrails → Semantic Apply → Audit / Undo. Closed inputs and outputs preserve one mutation authority.
Guides
- Runtime Security — allowlist, scope, injection defense
- Local AI Privacy — snapshot and local-only boundary
- Audit & Guardrails — explainability and rollback
Cross-product invariants
| Invariant | Enforcement |
|---|---|
| No raw DOM to AI | Semantic Snapshot only |
| No AI-created capability | Candidate ID ranking only |
| No free mutation | Intent/schema/allowlist/guardrails |
| No silent Block overwrite | Conflict fail unless --force |
| No Inspector bypass | Delegation to existing controller |
Limits
No legal certification is claimed. Cloud AI, Inspector UI, hosted community registry, and signing are outside the frozen 1.4.0 scope.