Observed
Recorded behavior or an artifact inside the authorized review boundary. It says what was observed, not that the claim is universally true.
Trust, context, and control · Product preview
Panda's trust model starts with explicit context, names what evidence can support, and ends with host-final authority. The current frontend remains a local preview.
Start with the boundary
A review should make the authorized evidence, exclusions, freshness, retention, and budget legible before anyone relies on its findings.
Current connection state
Boundary map
Findings tied to the supplied artifacts, declared contract, and resolvable evidence references.
Universal correctness, missing evidence, or an externally observed outcome without a verifier.
Context manifest
Included
Excluded
Evidence lineage
Evidence references should resolve inside the declared boundary or to a lineage-bound artifact. Their class tells the host how much the result can support.
Recorded behavior or an artifact inside the authorized review boundary. It says what was observed, not that the claim is universally true.
A person or host system's claim, disposition, or outcome report. Useful context, but not independent verification by itself.
An external verifier or independent adjudicator supports the claim on the covered subset. The scope and limitations still travel with it.
If the evidence boundary cannot support the claim, the honest result can be unknown, disagreement, abstention, or needs input.
Current connection state
The pages use server-rendered fictional fixtures to show the review object and method. They do not call a model, upload context, access a repository, persist a disposition, or execute an external action.
A connected Core service would need approved identity, tenancy, retention, authorization, evidence, provider, error, and audit contracts before this surface could describe an operational run.
Trust questions
Trust claims should describe the boundary they can actually support, especially while the service remains a preview.
It represents the declared review boundary: included and excluded materials, freshness, retention, and budget. In the product preview it is a local fixture; no customer artifact is uploaded or retained.
No. A manifest is evidence of declared scope, not proof that an operating-system sandbox prevented every possible leak. Connected execution would require separately verified controls.
No. The visible disposition labels are illustrative only. The frontend preview has no persistence, connected model call, upload, credential, or external action.
This public surface is a server-rendered product preview over local fictional fixtures. The connected Core review service, providers, retrieval, uploads, and analytics remain disabled; local GoTrue/Panda account flows live behind an explicit development configuration on the non-public product routes.
Inspect the boundary in use