AI-use policy / Bounded

Models may draft and inspect. Evidence and policy decide release.

External content is treated as untrusted data. Generators receive a bounded dossier, cannot access deployment credentials, and cannot edit protected workflows or security policy.

Independent review required
01

Required provenance before generated content ships

  • Source set and hashes
  • Prompt-template version
  • Provider and model identity
  • Sampling configuration
  • Output disposition
  • Resulting content diff and receipt
02

Private reasoning

Kedabek does not publish model chain-of-thought. It publishes enough inputs, evidence, outputs, rubrics, and tests to evaluate the released decision without exposing private reasoning traces.

03

No silent external routing

Local-only is the default. API and hybrid modes require explicit customer configuration, data classification, credentials, provider, budget, and agreement.