Skip to main content

Data governance

Merion’s private-alpha capture path is local-first. The default factory policy allows local service delivery while requiring review before evidence can be used for evaluation or customer improvement. Training, publication, and aggregate use are denied by default. Signing in, setting up capture, or installing the local receiver does not authorize cloud sync. Cloud policy is configured separately, planning is read-only, and queueing requires explicit approval.

Local evidence boundary

  • Factory state is stored under .merion/ by default.
  • .merion/ is excluded from Git in the Merion repository.
  • Source snapshots are content-addressed and remain local.
  • Normal CLI output is redacted.
  • Full locally authorized payloads require explicit sensitive-output flags.
  • Initialization never creates a GitHub remote or publishes evidence.
  • Cloud credentials are not stored in policy files, manifests, SQLite, or CLI output.
  • Content-free metadata, reviewed evidence, derived artifacts, and raw source are separate sync tiers.
  • Raw source requires explicit per-manifest approval even when a cloud workspace is active.

Governed cloud boundary

Merion’s cloud layer is intended for managed storage, compute, and analysis over customer-approved data. A cloud policy pins the tenant workspace, personal or organization scope, allowed analysis purposes, content tiers, maximum classification, residency region, retention window, and encryption requirements. The local lake remains authoritative. Cloud results return as derived artifacts with provenance; they do not overwrite source evidence. Cross-tenant aggregation is not implied by cloud sync and remains denied unless a separate data-use policy explicitly authorizes it.

Human-accountable decisions

Merion can automate evidence collection and deterministic checks. It does not silently decide:
  • whether an outcome was actually acceptable;
  • whether a task represents normal work;
  • whether evidence may be used for evaluation or training;
  • whether a verifier captures the domain expert’s intent;
  • whether a task, harness, environment, or verifier should be approved;
  • whether an experiment result is sufficient for release.

Sensitive information

Do not capture production secrets, regulated records, or customer data until the relevant workflow charter, permissions, retention rules, environment, verifier stack, and release plan have been approved. The existence of local storage is not itself authorization to collect or use sensitive data.
Last modified on August 25, 2026