Privacy Model
Disclosure boundary
A Capability discloses the service contract and evidence needed to evaluate delivery while keeping the Creator’s method under the Creator’s control.
| Information | Visibility | Purpose |
|---|---|---|
| Capability description, Defined Claim, price, and version | Buyer-visible; public when distributed through a public channel | Define the purchase |
| Evidence requirements and settlement conditions | Buyer-visible before purchase | Define assessment and recourse |
| Prompts, private knowledge, memory, data logic, and execution strategy | Creator-controlled | Protect the method |
| Buyer inputs and execution outputs | Authorized transaction participants | Complete the work |
| Execution ID, Capability version, provisional result, Challenge deadline, and claim-relevant evidence commitment or summary | Public during the Challenge Window | Make the public Challenge Window usable |
| Raw Execution Record and Delivery Evidence | Transaction parties and authorized reviewers | Support Verification and Evidence Review |
| Resolved outcomes and aggregate Capability History | Public summary; sensitive transaction detail remains access-controlled | Support Buyer diligence across channels |
Evidence access
Delivery Evidence is limited to what the Defined Claim requires. Public metadata supports discovery and Challenge filing; raw evidence is available only to the parties and Resolver under the applicable access and retention rules.
Privacy controls
Claims, records, outputs, and evidence follow the access, retention, and disclosure rules defined for the applicable Capability. Private workflow logic remains Creator-controlled unless the Creator expressly authorizes disclosure.