Trust Center

Trust comes from reviewable boundaries.

This page separates product state, technical evidence, synthetic showcases and open boundaries. It is not a certificate. Every public example uses invented companies with .example domains. Real operator figures from Search Console, Bing or Analytics are not product evidence and do not appear here.

CLAIMS

A green test is not a customer outcome

An installer test proves installation. HTTP 200 proves availability. externalWrites 0 proves that a test run changed no external system. None of these findings proves rankings, citations, leads, time saved or revenue.

STATUS

Four terms keep claims apart

Built means code exists. Verified means a named test produced a reproducible result. Observed means a measurement exists for a suitable period. Open means the claim is not yet supported. The Proof Ledger follows this distinction.

SHOWCASE

Every business scenario is explicitly fictional

Velunor Bikes at velunor-bikes.example, Qevora Systems at qevora-systems.example and Studio Talvori at studio-talvori.example are invented companies. Names, domains, goals, KPIs, approvals and outcome values exist only to demonstrate the product. They are not customer references.

RELEASE

SEO/GEO is a preview, not a generally sold release

The first implemented addon scope is evaluated with Founding Partners. There is no final signed public release artifact, self service checkout or general licence sale yet.

DIRECT

Direct accepts trusted local work only

OpenClaw and Hermes use bounded tools for read only work and local drafts in Direct. Direct is not process containment and is not intended for arbitrary foreign input.

SECURE

Secure has a different boundary in each runtime

OpenClaw Secure adds Docker protection but is not ready for untrusted or production use. Hermes Secure is unavailable and stops before mutation. One broad Secure claim for both runtimes would be false.

AUDIT WITNESS

The second Audit boundary is built and adversarially tested

Thirteen local tests cover sequence gaps, rollback, forks, foreign keys, modified ledgers, deleted tails, concurrent writers, ambiguous persistence and the same operating system account. The last case is deliberately rejected as independent. The dedicated reviewer deployment runs the Witness under a second identity; that evidence is limited to the reviewer host.

WINDOWS

Windows tests are not release evidence yet

Automated lifecycle tests run in isolated Windows test directories. They did not test a fresh customer machine or a signed package built from the current source. The real release lifecycle remains open for Windows, macOS and Linux.

OPERATING BOUNDARY

The local supervisor still shares one operating system account

The five services run as separated processes, but the standard setup uses the same user account. That does not create a kernel boundary. Production isolation needs separate accounts, containers or an equivalent platform boundary.

DATA

Product state and Google tokens have separate boundaries

Workspace, goals, evidence, actions, approvals, receipts and audit live in the local product database. Website and Bing use separate source paths. Google tokens stay server-side in the managed connector and never reach the browser, Local Agent, OpenClaw, Hermes or a model. The public website loads analytics only after consent. Form data is not sent to analytics.

SUPPLY CHAIN

A ZIP hash is not a publisher fingerprint

The SHA256 value of a ZIP archive verifies its bytes. It does not prove who published it. Publisher identity requires the full Public SPKI SHA256 fingerprint from an independent channel and comparison with the signing key. It must not be taken from the same ZIP or its sidecars. A final fingerprint will appear here only after unambiguous verification of the final release sidecars.

REPORT

Security findings have a direct contact

Responsible disclosure matters more than an invented seal. Reports go to francesco@scilipoti.de. There is currently no formal bug bounty program, guaranteed response time or external certification.

OPEN

The main open boundaries remain visible

They include complete workload containment, a final signed customer artifact, Google review and general customer release, and real customer runs on Windows, macOS and Linux. The separate Witness evidence from the dedicated review environment applies only to the reviewer host. General CMS, Bing and other writes still need their own connector contracts. The current 11 of 11 source records do not close any of these boundaries automatically.

Secure acquisition

Trust starts before installation.

These files are verification tools, not an approved customer package. The public release pointer has not been published. Once it is published, the acquisition bootstrap first verifies its signature and then validates the immutable release set with all seven targets and 56 file bindings. Only that verified set selects the eight files for the current system. The separately obtained verifier, trust pins and public release key remain independent trust anchors. It does not start MarketingOS. Compare the checksums of these files through an independent channel first.

Continue

Read the security model in detail

The security page explains the Direct Profile, Secure Profile and host runtime boundaries without shortcuts.

Read the security model