{
  "schemaVersion": "gships-review-packet-1",
  "packetId": "public-synthesis:public-policies",
  "stableId": "public-policies",
  "family": "public-synthesis",
  "slug": "public-policies",
  "title": "Accessibility, privacy, security, and terms",
  "status": "prepared-human-review-not-started",
  "release": {
    "releaseId": "public-alpha-2026-07-26-research-visuals-r14",
    "sourceCommit": "3eb036fce3d711336c8c605625895e8a2e799ab0",
    "corpusGeneratedAt": "2026-07-25",
    "frozenAt": "2026-07-26T22:50:50.000Z",
    "canonicalOrigin": "https://gships.dammonburden.com"
  },
  "paths": {
    "human": "/review/public-synthesis/public-policies",
    "family": "/review/public-synthesis",
    "packet": "/review-packets/public-synthesis/public-policies.c7d858af67cc37e3.json",
    "decisionTemplate": "/review-packets/public-synthesis/public-policies.c7d858af67cc37e3.decision-template.json",
    "worksheet": "/review-packets/public-synthesis/public-policies.c7d858af67cc37e3.worksheet.md",
    "byFingerprint": "/review-packets/by-fingerprint/c7d858af67cc37e3731607162018c6b0d445054963f469d3f05e1812d35ccd70.json"
  },
  "boundary": "Prepared review packet; human review has not started. This packet is not a completed review, endorsement, reviewer appointment, partnership, or authorization to act.",
  "governingPolicies": [
    {
      "id": "policy-editorial-governance-001",
      "version": "0.1.0",
      "path": "/editorial-policy",
      "recordType": "governing-policy",
      "fingerprint": "1f6a1f823e8bfe891b6a707c5dce2ee2337c0bb7d915b48d6060ca82b8da1b47",
      "snapshot": {
        "id": "policy-editorial-governance-001",
        "version": "0.1.0",
        "status": "foundation-policy-controls-not-yet-staffed",
        "adoptedForFoundation": "2026-07-25",
        "title": "Editorial governance and independent review",
        "publisher": "GShips Project",
        "maintainer": "Dammon Burden",
        "publisherInterest": "The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.",
        "currentBoundary": "No independent domain reviewer or review council is currently appointed. Foundation records and outlines may not be represented as independently reviewed.",
        "reviewerSelection": [
          "Publish the reviewer’s name, relevant credentials or lived expertise, review scope, compensation status, and declared conflicts with consent.",
          "Select for the actual claim domain rather than general prestige; include affected-community and disability-led expertise where rights or access are involved.",
          "Do not treat an employee, investor, customer, sponsor, source author, or directly supervised collaborator as independent for the affected claim."
        ],
        "reviewProcess": [
          "Provide the exact claim, sources, locators, assumptions, counterevidence, transfer limits, and proposed evidence dimensions.",
          "Record approve, revise, contest, or reject at claim level; silence and event attendance never count as review.",
          "Publish material minority findings and the editor’s reasoned response.",
          "High-consequence medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use claims require two qualified independent reviewers with complementary scopes.",
          "A reviewer may recuse at any time; unresolved conflicts or missing expertise block the reviewed label."
        ],
        "appealAndCorrection": [
          "A correction receives a reference identifier and triage record; safety-critical allegations receive priority.",
          "A material editorial decision may be appealed to a reviewer not involved in the original decision once such a panel exists.",
          "Substantive reversals, unresolved disputes, and removed conclusions receive a dated public record that protects reporter privacy.",
          "No sponsor, customer, founder, or reviewer may purchase, suppress, or unilaterally assign an evidence grade."
        ],
        "publicationGate": "Public 1.0 requires named review coverage across every Academy track, documented high-consequence two-person review, a material-corrections log, reviewer conflict records, and an operating appeal path.",
        "correctionPath": "/corrections"
      }
    },
    {
      "id": "policy-dual-use-001",
      "version": "0.1.0",
      "path": "/dual-use",
      "recordType": "governing-policy",
      "fingerprint": "81637e2849f9c0866d23f7174eb9a2ce522b86313167ebf5022fca122d6e506c",
      "snapshot": {
        "id": "policy-dual-use-001",
        "version": "0.1.0",
        "status": "planned-controls-not-yet-operational",
        "adoptedForFoundation": "2026-07-25",
        "title": "Civil, defensive, and rights-preserving use boundary",
        "summary": "GShips may research safety, resilience, logistics, communications, recovery, and cyber defense only within explicit end-use, rights, and independent-review controls. Calling an activity defensive is never sufficient by itself.",
        "scopeTrigger": "Apply dual-use review before accepting or materially advancing customer, funder, collaborator, operational, procurement, or publication-sensitive work whose capability, data, end use, or transfer could reasonably enable a prohibited use. Public non-actionable education still follows prohibited-content and sensitive-publication controls.",
        "allowedInPrinciple": [
          "Safety engineering and independently assessed protection",
          "Resilience, graceful degradation, recovery, and disaster response",
          "Civil logistics, maintenance, communications, and knowledge continuity",
          "Cyber defense, secure software, incident response, and recovery",
          "Rights-preserving health, accessibility, ecology, education, and governance research"
        ],
        "prohibited": [
          "Identification, tracking, prioritization, or engagement of people or assets for force, weapons, repression, or offensive operations; safety navigation, astronomy, collision avoidance, search and rescue, and independently governed planetary defense are not prohibited by this clause",
          "Weapons command-and-control or targeting support",
          "Offensive access, persistence, exploitation, or destructive cyber payloads",
          "Mass surveillance, biometric repression, or political-control systems",
          "Autonomous force application",
          "Coercive reproductive, medical, genetic, disability, or civic control",
          "Nonconsensual experimentation or treating residents as research instruments"
        ],
        "reviewRequiredBeforeAnyRelevantWork": [
          "Customer, funder, collaborator, jurisdiction, beneficial-owner, and end-use screening",
          "Export-control and sanctions review by qualified counsel when applicable",
          "Written scope, allowed-use, prohibited-use, audit, termination, and incident clauses",
          "Independent stop-work authority with a named alternate and founder recusal",
          "Sensitive-publication and information-hazard review",
          "Whistleblowing, escalation, incident response, appeal, and anti-retaliation paths",
          "Aggregate transparency reporting that protects legitimate privacy and security"
        ],
        "currentBoundary": "No screening body, independent stop-work authority, contractual controls, or appeal body currently exists. Therefore no relevant customer, defense, dual-use, or operational engagement is authorized by this policy.",
        "changeControl": "Material changes require a dated public rationale, independent review, and may not be approved by the founder alone.",
        "correctionPath": "/corrections"
      }
    }
  ],
  "reviewContract": {
    "questions": [
      {
        "id": "question-1",
        "text": "Does the public synthesis accurately distinguish evidence, editorial interpretation, normative rules, current status, and unresolved uncertainty?",
        "required": true
      },
      {
        "id": "question-2",
        "text": "Are boundaries, decision rules, relationship language, privacy, access, and what-would-change conditions complete and understandable to affected publics?",
        "required": true
      },
      {
        "id": "question-3",
        "text": "Do linked records remain the source of entity facts and computed counts without being silently copied, ranked, endorsed, or promoted into stronger evidence?",
        "required": true
      }
    ],
    "exclusions": [
      "A synthesis review does not approve every linked record, computed count, preview row, or operational code path.",
      "Favorable wording review is not legal, medical, engineering, security, partnership, submission, launch, or governance authorization."
    ],
    "requestedScopeCodes": [
      "accessibility-disability-justice",
      "affected-public-rights",
      "defensive-cyber-safety",
      "governance-law-rights",
      "information-science",
      "visual-science-communication"
    ],
    "dispositions": [
      "approve",
      "revise",
      "contest",
      "reject",
      "recuse"
    ],
    "prohibitedInputs": [
      "private legal names or contact details",
      "identity documents or raw credential files",
      "accessibility or medical records",
      "confidential conflict evidence",
      "classified, export-controlled, proprietary, or exploit material"
    ],
    "freshness": {
      "maximumDecisionAgeFromFreezeDays": 180,
      "eventOccurrenceRule": "Not applicable to this packet family."
    },
    "completionRule": "Every primary record must receive the required number of valid, current-fingerprint approvals; every complementary scope group and required domain must be covered; any unresolved revise, contest, or reject disposition blocks publication.",
    "highConsequenceRule": "Named medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use conclusions require two distinct qualified independent humans covering complementary domain-method and rights/public-interest scopes."
  },
  "primaryRecords": [
    {
      "recordType": "page-synthesis",
      "recordId": "accessibility",
      "title": "Accessibility",
      "publicPath": "/accessibility",
      "recordFingerprint": "0d41ecb28ffc29cbd2e8a55a724b91bd94e9c2d8ceb1ac3964bb050bd50d0703",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "affected-public-rights",
              "information-science",
              "visual-science-communication"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "accessibility",
        "packet": "public-policies",
        "route": "/accessibility",
        "title": "Accessibility",
        "eyebrow": "Policy",
        "heading": "Accessibility",
        "description": "Accessibility commitments, known limits, testing boundaries, and correction paths.",
        "authoredSections": [
          "WCAG 2.2 AA target",
          "keyboard and assistive-technology support",
          "reflow, motion, contrast, and alternatives",
          "known manual-review gaps",
          "accessibility correction path"
        ],
        "noticesAndBoundaries": [
          "Automated checks do not establish full accessibility or disabled-user acceptance.",
          "Public 1.0 requires manual, platform, zoom, and disabled-participant evidence."
        ],
        "decisionRules": [
          "Every interactive needs an equivalent text or table presentation.",
          "Accessibility findings are noncompensatory release gates."
        ],
        "reviewBoundary": "Review commitments and known limits; implementation conformance requires manual and automated evidence.",
        "whatWouldChange": "User findings, standards changes, platform regressions, or completed manual evidence would require revision.",
        "linkedRecordKeys": [
          "visual-provenance-ledger:chapter-and-social-art"
        ],
        "rendererBinding": {
          "schemaVersion": "gships-page-renderer-binding-1",
          "status": "source-and-rendered-main-bound",
          "bindingFingerprint": "313c95d1cb2ae5ac6f9867bc94e69bd7220553677805b3b43beb416925d47693",
          "sourceAggregateSha256": "fc3a0a0bf781db22318e37aebd48bc8e4f27b75260bffbe910256503b8106a5e",
          "renderedRouteSurface": {
            "route": "/accessibility",
            "normalizedMainSha256": "27a0d45daf9665b0ee5a3c3ff56533c2a95203c8dc88ee7c94a0ac51b6328e45",
            "normalizedMainBytes": 1269
          }
        }
      }
    },
    {
      "recordType": "page-synthesis",
      "recordId": "privacy",
      "title": "Privacy",
      "publicPath": "/privacy",
      "recordFingerprint": "146c3f33eaaef839c58d99c98c382b707e02c66f925a78cc7c31382d9b550c20",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "governance"
        ],
        "requiredDomainCodes": [
          "governance-law-rights"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "ethics-planetary-protection",
              "governance-law-rights"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "privacy",
        "packet": "public-policies",
        "route": "/privacy",
        "title": "Privacy",
        "eyebrow": "Policy",
        "heading": "Privacy",
        "description": "Public-data, form, analytics, infrastructure-log, retention, and sensitive-submission boundaries.",
        "authoredSections": [
          "cookie-free analytics",
          "provider and infrastructure logs",
          "form fields and purposes",
          "retention and deletion",
          "sensitive-data exclusions",
          "reviewer privacy"
        ],
        "noticesAndBoundaries": [
          "The site creates no account or review-response record through packet downloads.",
          "Hosting and analytics providers may still record bounded request data.",
          "Public forms must not receive credentials, identity evidence, private review decisions, or sensitive records."
        ],
        "decisionRules": [
          "Minimize fields, logs, recipients, and retention.",
          "Publish only consented, redaction-reviewed reviewer fields."
        ],
        "reviewBoundary": "Review public privacy claims against actual provider, Worker, D1, analytics, and retention behavior.",
        "whatWouldChange": "Any provider, field, recipient, storage, analytics, logging, retention, jurisdiction, or review-publication change requires revision.",
        "linkedRecordKeys": [
          "governance-control:operational-control-activation"
        ],
        "rendererBinding": {
          "schemaVersion": "gships-page-renderer-binding-1",
          "status": "source-and-rendered-main-bound",
          "bindingFingerprint": "313c95d1cb2ae5ac6f9867bc94e69bd7220553677805b3b43beb416925d47693",
          "sourceAggregateSha256": "fc3a0a0bf781db22318e37aebd48bc8e4f27b75260bffbe910256503b8106a5e",
          "renderedRouteSurface": {
            "route": "/privacy",
            "normalizedMainSha256": "ac8b986021be641a84ab4e62a1a963b6f05d60513783e776676a4ae1f5dfd395",
            "normalizedMainBytes": 1982
          }
        }
      }
    },
    {
      "recordType": "page-synthesis",
      "recordId": "security",
      "title": "Security",
      "publicPath": "/security",
      "recordFingerprint": "f28942cfeec84284b435e5dc8d34fd98ff8e1bc1b6b2e7ba5da0f24884bc8ee6",
      "reviewRequirements": {
        "minimumIndependentApprovals": 2,
        "highConsequenceDomains": [
          "cybersecurity",
          "dual-use"
        ],
        "requiredDomainCodes": [
          "defensive-cyber-safety"
        ],
        "requiredComplementaryScopeGroups": [
          {
            "id": "domain-method",
            "scopeClass": "domain-method",
            "oneOf": [
              "defensive-cyber-safety",
              "security-assurance"
            ]
          },
          {
            "id": "rights-public-interest",
            "scopeClass": "rights-public-interest",
            "oneOf": [
              "affected-public-rights"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "security",
        "packet": "public-policies",
        "route": "/security",
        "title": "Security",
        "eyebrow": "Policy",
        "heading": "Security",
        "description": "Security headers, forms, disclosure, dependency, secret, release, recovery, and civil-and-defensive boundaries.",
        "authoredSections": [
          "security contact and security.txt",
          "headers and isolation",
          "form validation and abuse controls",
          "secret and dependency scanning",
          "deterministic release evidence and rollback",
          "defensive-only disclosure boundary"
        ],
        "noticesAndBoundaries": [
          "Do not send exploit details through public forms.",
          "No offensive testing, autonomous weapons, weapon integration, or uncontrolled critical-infrastructure material."
        ],
        "decisionRules": [
          "Fail closed on invalid input and release evidence.",
          "Preserve rollback, incident, correction, and responsible-disclosure paths."
        ],
        "reviewBoundary": "Review security claims against production behavior and independent assessment; this synthesis is not a penetration test or certification.",
        "whatWouldChange": "A vulnerability, provider, header, form, storage, dependency, secret, release, recovery, or threat-model change requires revision.",
        "linkedRecordKeys": [
          "governance-control:dual-use",
          "governance-control:operational-control-activation"
        ],
        "rendererBinding": {
          "schemaVersion": "gships-page-renderer-binding-1",
          "status": "source-and-rendered-main-bound",
          "bindingFingerprint": "313c95d1cb2ae5ac6f9867bc94e69bd7220553677805b3b43beb416925d47693",
          "sourceAggregateSha256": "fc3a0a0bf781db22318e37aebd48bc8e4f27b75260bffbe910256503b8106a5e",
          "renderedRouteSurface": {
            "route": "/security",
            "normalizedMainSha256": "c6061f72d789423b688c654f774251c26f5bdeb51ed4c52c7d59807d9028bd5a",
            "normalizedMainBytes": 1401
          }
        }
      }
    },
    {
      "recordType": "page-synthesis",
      "recordId": "terms",
      "title": "Terms",
      "publicPath": "/terms",
      "recordFingerprint": "80aa859d0e297f125ec3716c493c56b0876c4d0de91f520600634c2e3903ba9e",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "affected-public-rights",
              "information-science",
              "visual-science-communication"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "terms",
        "packet": "public-policies",
        "route": "/terms",
        "title": "Terms",
        "eyebrow": "Policy",
        "heading": "Terms",
        "description": "Public-alpha information, relationship, professional-advice, external-link, and authorization boundaries.",
        "authoredSections": [
          "informational public-alpha status",
          "no professional advice",
          "no relationship or endorsement",
          "external links",
          "no external action authorization",
          "license and correction references"
        ],
        "noticesAndBoundaries": [
          "The site does not provide engineering, medical, legal, investment, safety, or mission authorization.",
          "No publication authorizes incorporation, outreach, application, registration, travel, purchase, submission, sponsorship, or partnership."
        ],
        "decisionRules": [
          "Represent current status and relationships truthfully.",
          "Keep external action separately authorized."
        ],
        "reviewBoundary": "Review plain-language terms and their consistency with actual behavior; legal interpretation requires qualified jurisdiction-specific advice.",
        "whatWouldChange": "Entity formation, a transaction, formal relationship, jurisdiction, provider, service, or accepted legal review would require revision.",
        "linkedRecordKeys": [],
        "rendererBinding": {
          "schemaVersion": "gships-page-renderer-binding-1",
          "status": "source-and-rendered-main-bound",
          "bindingFingerprint": "313c95d1cb2ae5ac6f9867bc94e69bd7220553677805b3b43beb416925d47693",
          "sourceAggregateSha256": "fc3a0a0bf781db22318e37aebd48bc8e4f27b75260bffbe910256503b8106a5e",
          "renderedRouteSurface": {
            "route": "/terms",
            "normalizedMainSha256": "79cdb21510048392aadaccaa8a126a10b09da5b238f5db9eb5183e731b7f9181",
            "normalizedMainBytes": 1158
          }
        }
      }
    }
  ],
  "linkedRecords": [
    {
      "recordType": "governance-control",
      "recordId": "dual-use",
      "title": "Civil, defensive, and rights-preserving use boundary",
      "publicPath": "/dual-use",
      "recordFingerprint": "114198e83a2803d975bbae46e110ca7dd644b9f93ff7669867dbff2474df9c30"
    },
    {
      "recordType": "governance-control",
      "recordId": "editorial-governance",
      "title": "Editorial governance and independent review",
      "publicPath": "/editorial-policy",
      "recordFingerprint": "ca45c6fde5591e6f3897e7c20927609a776d50ca3b6ba0c5cdedc132417baa0a"
    },
    {
      "recordType": "governance-control",
      "recordId": "operational-control-activation",
      "title": "Operational control activation register",
      "publicPath": "/review",
      "recordFingerprint": "dd931ff254e0ff8105e0952338587c2dcbce71d78450a07a176308262d2c8289"
    }
  ],
  "referenceSnapshots": [],
  "packetFingerprint": "c7d858af67cc37e3731607162018c6b0d445054963f469d3f05e1812d35ccd70"
}
