RV/overview
2026-06-15 · UTC audit chain valid
RV PRIVACY V1OPERATOR-BLINDNO RECOVERY KEY

Blinded research operations without identity spillover

Precision workflow for acquisition, judging, analysis, governance, and controlled exports. Direct identifiers stay in the user-held vault; role workspaces see scoped capability summaries only.

Identity modelVAULTclient-encrypted mappings
Access modelCAPscoped principals
ArtifactsTICKETopaque read links
ExportsLOCALbundle pseudonyms only
Direct identifiers, identity mappings, invitation secrets, raw capability refs, and storage paths are excluded from normal operator surfaces.
PRIVACY BOUNDARY

Workspaces

role-scoped
AreaPurpose
Study registryProtocol setup, lock, assignment, and lifecycleOpen
Target corpusTarget media and frozen poolsOpen
AcquisitionViewer sessions with concealed target identityOpen
Blind judgingAnonymized 4-choice ranking packetsOpen
AnalysisPre-registered confirmatory reportingOpen
GovernanceAudit, retention, and controlled exportsOpen

Access paths

separate contexts

Redeem an anonymous invitation for role-scoped workspaces. Account-backed vault access is separate and requires an authenticated account session.

Redeem anonymous invitation
Operator limits

Railway/domain metadata remains visible. Anonymous capabilities do not unlock the account vault, and vault decrypt keys do not exist server-side.