These documents define the safety, privacy, evidence, and interoperability contracts for the AntiFlock working title. Implementations may add capability, but they may not weaken these contracts without an accepted architecture decision and an explicit security and privacy review.
Start with:
- Vision
- Architecture
- Threat model
- Evidence model
- Privacy invariants
- Protection states
- Initial alert catalog
- Terminology
- Data retention
- Community intelligence policy
- Scrambler safety model
- API contracts
- Event contracts
- Signing contracts
- OPEN decisions, unconnected features, and release gates
- Reference vertical-slice release status
- Local operator runbook
- Nano watchdog boundary and runner roadmap
- Continuous agent and Nano watchdog loop
- Architecture decisions
Normative words such as MUST, MUST NOT, SHOULD, and MAY are used in their ordinary requirements sense. A protobuf comment and its corresponding contract document are both normative. If they conflict, choose the more privacy-preserving and fail-safe behavior and open an ADR to resolve the ambiguity.
AntiFlock is an internal working title. An existing project uses that name
in an overlapping area. No public launch, namespace claim, trademark claim,
or implication of affiliation is authorized until the name is cleared,
permission or partnership is established, or a distinct public name is
selected. This is a documented collision, not a legal conclusion.