CANONICAL CASE BOUNDARY
Investigative privacy boundary
R/IV uses private Sites storage and does not automatically expose cases, search histories, repository queries, unpublished findings, visitor-supplied information, artifacts, logs, hypotheses, or authentication metadata.
Access without signup
No R/IV account or signup is required. The request boundary issues this browser a Secure, HttpOnly, SameSite=Lax cookie and derives a SHA-256 owner key for anonymous cases.
Anonymous privacy is browser-session isolation, not identity-grade authentication. Clearing cookies, using a private window, or changing browsers can remove access to anonymous cases. Export important investigations first.
Case and artifact visibility
New investigations and imported artifacts default to PRIVATE. Publication is a separate deliberate workflow and is never performed automatically.
Data handling and optional processing
Case objects, immutable versions, acquisition receipts, hashes, proof dependencies, and audit events use structured storage. Lawful bounded captures and user-imported bytes may use private object storage. Imports are SHA-256 hashed and remain candidate evidence: a hash does not authenticate authorship, origin, relevance, or truth.
Text extraction can run inside R/IV. OCR, PDF extraction, audio/video transcription, embeddings, semantic queries, and citation-grounded assistance require an explicitly configured server-side provider credential and a deliberate investigator action. When configured, selected artifact bytes, a query, or bounded case context are transmitted to that provider for the requested operation. When no provider is configured, R/IV reports NOT CONFIGURED and transmits nothing. Machine output is stored separately, remains unverified, and is never evidence or an adjudicated finding.
OpenAI Sites does not expose data or inference residency controls to this application. R/IV must not be described as residency-controlled.
Reset, export, and restoration
RESET CURRENT CASE requires exact case-specific confirmation and creates a pre-reset snapshot before clearing only the selected case’s investigative rows. RESTORE CASE requires a deliberate checkpoint choice and verifies ownership, snapshot hash, case identity, and referenced private artifacts before mutation. Reset and restore do not clear browser storage, unrelated databases, other cases, site preferences, or unrelated routes. Cases export a portable JSON evidence package; artifact bytes are not embedded automatically.
Deletion
DELETE CASE requires exact case-specific confirmation. The deletion route removes private object-storage keys associated with the selected case and its recovery checkpoints before deleting its owned database row and dependent records. If object deletion cannot be completed, database deletion is blocked. Other cases and unrelated site data are not targeted. Native recoverability after deletion is not guaranteed, so export important work first.
Analytical boundary
Deterministic duplicate, identity-collision, temporal-conflict, contradiction-candidate, and source-independence diagnostics are triage signals. They do not merge identities, delete duplicates, resolve conflicts, authenticate records, or promote findings automatically. R/IV does not fabricate transcripts, hypotheses, evidence, search results, missing records, findings, or /THE BREAK.
