M0 accepts only local synthetic demonstrations. Do not use it to send customer-specific queries or wallet material. Never provide seeds, spending/viewing keys or payment credentials. There is no genuine private-query transport.
A future private release must locally verify the approved platform and workload, a fresh challenge, and ownership of the live TLS key before serialization/transmission. Tor is mandatory, with remote DNS and no hidden collateral-fetch bypass. The local UI must continue to share this core. Provider verification assertions cannot replace local verification.
Trust remains in the customer device, reviewed software, verifier and release distribution, hardware vendor and accepted platform stack. Attestation is not a proof of runtime correctness, chain consensus, no retention or resistance to all traffic analysis.
Security reports should contain synthetic reproductions only. Do not include cloud credentials, private keys, real query selections or unredacted customer data in public issues. No reporting address or disclosure SLA is established for this local repository.