Skip to evidence

METHOD v1.0 · READ BEFORE QUOTING

Packets are facts. Motives are not.

A result describes only what this exact build did in this exact test. It does not establish purpose, retention, training use, sale, safety, or behavior in another account, region, operating system, or scenario.

01

Fresh state

Every repeat receives a new CLI config and data directory. User credentials, repositories, extensions and background processes stay outside the test.

02

One process

One CLI runs through one local proxy. The process receives only test credentials and a fixed prompt.

03

Three repeats

A route becomes stable only at 3/3. Mixed observations keep their frequency. Missing coverage becomes opaque or inconclusive.

04

Two evidence layers

Connection evidence answers where. Decrypted HTTP evidence can answer method, route shape and field names. TLS failure never becomes “no traffic.”

05

Redaction first

Header values, queries, bodies, prompts, outputs, paths, tokens and IP addresses never enter the public manifest.

06

Scoped language

Observed means this build, platform, config, scenario, network path and timestamp. It never means every user.

OBSERVED · NOT OBSERVED · OPAQUE · INCONCLUSIVE · NOT TESTED

REPRODUCTION

Inspect the sanitizer before trusting the result.

The tracked exporter is scripts/mitm-sanitize.py. Dataset and schema are public. Raw capture hashes let a responsible reviewer verify an exchanged artifact without us publishing secrets.

DATASET SCHEMA

CLAIMS WE WILL NOT MAKE

Traffic is evidence of a request, not a motive.

We do not call a product spyware, private, safe or unsafe. We do not infer retention, sale, training use or identity tracking from a destination. Those claims require different evidence.