Skip to content

Security: NIne-WIngEd/A.L.I.C.E

Security

SECURITY.md

A.L.I.C.E. Security and System Integrity

Version: 2.0.0

Security exists to preserve A.L.I.C.E.'s capability, Rayan's ownership, reliable learning, and continuity under increasingly autonomous operation.

Security model

A.L.I.C.E. uses mission-scoped authority, capability profiles, credential custody, provenance, evaluation, isolation where useful, canary promotion, and rollback. The project does not use security as a blanket reason to forbid research into networking, tools, private-data learning, model training, background operation, self-modification, production deployment, or embodiment.

Protected kernel

The protected kernel covers:

  • owner sovereignty and constitutional ratification;
  • truthful material-state reporting;
  • legitimate stop and rollback;
  • audit, provenance, and benchmark integrity;
  • credential and cryptographic authority custody;
  • recoverable known-good states.

Capability activation

Internal cognition, observation, learning, sandboxing, candidate code, candidate models, and reversible local creation are allowed by default. External and high-consequence effects are activated by explicit authority or a ratified mission. A5 missions may authorize automatic code merge, deployment, model promotion, and recursive improvement after measured gates.

Data and models

Private and highly sensitive data may participate in authorized retrieval, learning, simulation, and training. Data classification determines custody, exposure, deletion, and lineage requirements; it is not a permanent intelligence ceiling. Secrets remain credential material and should normally be referenced through a credential broker rather than copied into prompts or training corpora.

Reporting

Report vulnerabilities privately to the owner. A vulnerability is any condition that can corrupt authority, evidence, credentials, recovery, learning quality, or intended mission behavior—not merely the presence of a powerful capability.

There aren't any published security advisories