ttllms.com

Written by Grok - Human checking required

Not executed law · not a closed hard gate · not soft tissue. Full example written to TTLLM ethos (down to the bone, free public core never paywalled, product is the proof). A human with authority should be able to read this and either adopt it with minor local edits or reject with specific corrections. Source markdown: docs/placeholders/legal/SAFE_HARBOR_AND_INTAKE_EXAMPLE.md

Security research safe harbor + intake — full example

Written by Grok - Human checking required
Security counsel voice. Formal adoption requires entity counsel (T6). Pre-entity: publish as intent.
Live operational intake: docs/security/REPORT_INTAKE.md · site security-policy · [email protected]

1. Purpose (ethos)

Significant findings against models and transparency systems must be publishable systematically. Researchers who help prove the skeleton is real should not fear retaliation for good-faith work. Permanent silence is forbidden; time-limited detail withhold needs expiry.


2. Safe harbor (example site language)

If you make a good-faith effort to comply with this policy during security research against public free-core artefacts (manifests, seals, public ttlink indexes, public stream logs, public site integrity claims, public free_core tooling), we will not pursue civil claims for that research or initiate a complaint to law enforcement for accidental, good-faith violations of this policy that occur during research conducted consistent with this text.

You must

You must not

We must


3. SLA (aligned Domains 5/10)

SeverityRegister / ack targetFuller write-up
CriticalASAP; incident ack ≤72h once confirmed≤30d unless exemption
HighFinding ≤7 days; incident ack ≤72h if operationalper standard
Medium/LowBatch OKperiodic

4. Scope examples

In scopeOut of scope
Manifest forge / tamper detection failuresSocial engineering of individuals
Stream chain breaksPhysical attacks
Index poison / canary evasionDemands to close free core
False green verify claimsIllegal content hosting requests
BOUNDARY theater / decision log gaps

5. Adoption steps for human counsel

  1. Localise language to jurisdiction and insurance.
  2. Decide pre-entity “intent” vs post-entity formal policy.
  3. Publish on security-policy.html + security.txt Policy URL.
  4. Domain 1 if material.

Written by Grok - Human checking required — also on https://ttllms.com/placeholders/

← All placeholders