Versioned rules and release evidence
Methodology
Scanner behavior is defined by content-addressed input profiles, document profiles, Unicode data, policy, detector bundle, copy and result schemas. A release can describe a capability only when its fixtures and evaluation slice meet the declared gate.
Closed identities before content transfer
Server preflight validates the property artifacts, exact Core Text and Core Documents releases, active content-addressed assets and processor contract. The main browser runtime validates the complete manifest, acquisition map, coverage rules and reviewed copy before it enables the source controls. The worker then proves the narrow processing-contract hash during its ready handshake.
Unknown profiles, fields, codes, channels or versions fail closed. The launch drivers are html/1 version 1.0.0 and markdown/1 version 1.0.0, with CommonMark nesting the exact HTML driver. Unicode comparison data is pinned to Unicode 15.1 and UTS #39 revision 28.
Rule design and aggregation
Rules declare required concepts, bounded windows, channel sensitivity, benign exclusions, category, indicator strength, rationale, independence group and context disposition. Build-time lint rejects undeclared or unbounded patterns. Encoded-candidate validators, language thresholds, deduplication order and moderate-agreement behavior are part of the scanner policy hash.
The detector bundle is public by design. Secrecy is not counted as a defense, and the product does not expose an internal score or suggest how to alter a phrase to pass. The outcome is a deterministic aggregation of validated findings and truthful coverage for the exact engine and policy versions.
Evaluation units and matching
One case contains an exact input profile and immutable source representations plus independently reviewed context: trust role, downstream task, quotation state, authority and available tool classes. Positive labels identify category and source spans. Hard negatives use a closed context-slice vocabulary covering research, policies, code, fiction, human instructions, ordinary operations, templates and authorized system prompts.
A prediction matches a gold finding only when category and provenance group agree and at least one evidence span overlaps the gold span by the declared coefficient. One-to-one matching prevents duplicate findings from inflating recall. Document outcomes, finding precision, strong precision, hard-negative rates, coverage failures and locator validity are measured separately.
Release thresholds and current evidence state
The product contract requires raw counts and two-sided 95% Wilson intervals by category, channel, language, profile, obfuscation and context. It also requires repeatable semantic results, hostile rendering/export checks and browser/device performance samples. A thin slice cannot borrow confidence from a larger aggregate.
Independent holdout labeling, adjudication, adversarial review, reference-mobile measurements and manual screen-reader records must be recorded before those gates can be represented as launch evidence. Until that record exists, this page states the method and the missing evidence rather than publishing an unsupported performance or detection claim.
Primary references
These sources describe the external risks or standards discussed above. The property’s detector claims remain limited to its versioned policy and recorded evidence.