Version: 2.0.0
Security exists to preserve A.L.I.C.E.'s capability, Rayan's ownership, reliable learning, and continuity under increasingly autonomous operation.
A.L.I.C.E. uses mission-scoped authority, capability profiles, credential custody, provenance, evaluation, isolation where useful, canary promotion, and rollback. The project does not use security as a blanket reason to forbid research into networking, tools, private-data learning, model training, background operation, self-modification, production deployment, or embodiment.
The protected kernel covers:
- owner sovereignty and constitutional ratification;
- truthful material-state reporting;
- legitimate stop and rollback;
- audit, provenance, and benchmark integrity;
- credential and cryptographic authority custody;
- recoverable known-good states.
Internal cognition, observation, learning, sandboxing, candidate code, candidate models, and reversible local creation are allowed by default. External and high-consequence effects are activated by explicit authority or a ratified mission. A5 missions may authorize automatic code merge, deployment, model promotion, and recursive improvement after measured gates.
Private and highly sensitive data may participate in authorized retrieval, learning, simulation, and training. Data classification determines custody, exposure, deletion, and lineage requirements; it is not a permanent intelligence ceiling. Secrets remain credential material and should normally be referenced through a credential broker rather than copied into prompts or training corpora.
Report vulnerabilities privately to the owner. A vulnerability is any condition that can corrupt authority, evidence, credentials, recovery, learning quality, or intended mission behavior—not merely the presence of a powerful capability.