CONNECTED EVIDENCE CORE
Investigative privacy boundary
R/IV uses private Sites storage and does not automatically expose cases, search histories, repository queries, unpublished findings, visitor-supplied information, artifacts, logs, hypotheses, or authentication metadata.
Access without signup
No R/IV account or signup is required. The system issues this browser a secure, HttpOnly, SameSite cookie and stores only a SHA-256-derived owner key for anonymous cases. The raw browser identifier is not placed in client JavaScript, browser storage, rendered content, or application logs.
Anonymous privacy is browser-session isolation, not identity-grade authentication. Clearing cookies, using a private window, or changing browsers can remove access to anonymous cases. Export important investigations first. An existing ChatGPT identity may be recognized when present, but it remains optional.
Case and artifact visibility
New investigations and imported artifacts default to PRIVATE. Publication is a separate deliberate workflow and is never performed automatically.
Data handling
Case objects, immutable versions, acquisition receipts, hashes, proof dependencies, and audit events use the Site’s structured storage. Lawful bounded captures and user-imported bytes may use private object storage. Imports are SHA-256 hashed and remain candidate evidence: a hash does not authenticate authorship, origin, relevance, or truth. Secrets remain server-side.
OpenAI Sites does not expose data or inference residency controls to this application. R/IV must not be described as residency-controlled.
Export and restoration
Cases export a portable JSON evidence package preserving identifiers, relationships, versions, receipts, citations, audit records, artifact manifests, and hashes. Artifact bytes are not embedded automatically. Ownership-safe graph restoration remains blocked until deployment-verified; the system does not pretend otherwise.
Deletion requests
Site deletion is not assumed recoverable. Export important investigations first. The case deletion workflow records deletion intent, identifies affected versions and artifacts, and requires exact case-specific confirmation. The current safety gate records intent without erasing case data.
Platform and inference boundaries
No OCR, transcription, embedding, automated entity resolution, or model inference service is connected. R/IV does not fabricate transcripts, hypotheses, evidence, search results, missing records, findings, or /THE BREAK. Runtime quotas, retention guarantees, native storage versioning, scheduled execution, and streaming remain unclaimed unless the capability manifest records a verified test.