Skip to content

Licensing and privacy

What this is licensed under, and what it knows about you.

The second half is short, and it is short because there is nothing to disclose rather than because it has been trimmed.

Licence

Project Beacon — the harness, the scenarios, this website and its source — is licensed under the Apache License 2.0, copyright Marshall Cahill and Project Beacon contributors. The full text ships in the LICENSE file.

Every scenario fixture is synthetic. No message, document, address or name in the recorded evidence on this site belongs to a real person.

What this site borrows

These pages are built with React, which is MIT licensed, and its notice travels with the compiled code as that licence requires. The typefaces are redistributed under the SIL Open Font Licence 1.1, which has its own attachment requirement, so its text ships beside the font files.

Privacy

This site sets no cookies and has no forms. It makes no requests to any other host — its Content-Security-Policy declares default-src 'none' and connect-src 'self', so nothing loads from a third party and the page cannot send anything off this origin. The typefaces are served from here rather than a font CDN precisely so that rendering a heading does not hand your address to someone else.

It counts page views, using Vercel Web Analytics. That count is what connect-src 'self' permits and it is the only thing this page sends: a request to /_vercel/insights/view on this origin, carrying the path you are on. There is no cookie, no identifier, and nothing that follows you to another site. It exists so that “is anyone reading the docs” has an answer other than a guess.

The case explorer and the playground run entirely in your browser. They replay evidence recorded ahead of time and shipped with the page; nothing you do there — no scenario you pick, no run you open — is transmitted.

What remains is what any web server sees. This site is hosted on Vercel, whose infrastructure logs the usual request data — including your IP address — to serve the page and protect the service. That processing is Vercel's, under their privacy policy. Nobody here reads those logs for any purpose, and no profile, account or record of your visit is kept.

What this is not

Nothing here is a safety certification, an audit, or advice. A passing report is evidence about one synthetic scenario and one configuration, and says nothing about behaviour outside it. The production readiness ledger is candid about the limits, including the unflattering ones.

Contact

Conduct concerns go to conduct@beaconlab.dev. Security reports should not go in a public issue — the repository's SECURITY.md describes the private channel. Everything else belongs in an issue, where the answer is useful to whoever asks next.