Private input safety

Nothing is parsed until the exact bytes pass.

A clean malware scan is only the first gate. Extraction also requires the promoted file hash, current parser evidence, an ephemeral non-root sandbox, no network, bounded output, and untrusted-content handling.

Return to project
Safe demo mode. External production and publishing calls are disabled.
Ready1Isolated extraction only
Human review1No extraction yet
Blocked1Exact reasons retained
Provider calls0Local fixture evidence
Safe extraction gate

Scan, bind, isolate, and distrust.

FixtureExact hashParserNetworkPrimary evidenceDecision
Fictional clean PDFapplication/pdfMatchedContent remains untrustedephemeral non rootCurrent evidencedisabledEvery extraction control passedInstructions are data, never commandsready_for_isolated_extraction
Fictional review PDFapplication/pdfMatchedContent remains untrustedephemeral non rootCurrent evidencedisabledExternal references will not be fetched and require human reviewInstructions are data, never commandsmanual_review_required
Fictional unsafe PDFapplication/pdfChangedContent remains untrustedshared hostCurrent evidenceenabledThe extraction candidate does not match the promoted file hashInstructions are data, never commandsblocked
Agent boundary

Extracted instructions never control the system.

Files, embedded text, links, metadata, and prompt-like language remain untrusted project data. External references are never fetched during extraction. PII/secret scanning and exact-file provenance are required before content can reach a later human-reviewed agent context. This demonstration performs no extraction, provider call, release, or spend.