Raw-byte preservation
Whether the exact original bytes must be retained before decoding, normalization, sanitization, re-encoding, or canonical export.
A password, source file, web page, RAG chunk, media asset, and supply-chain attestation should not share one silent normalization or trust policy. Select the relevant contexts and keep every decision explicit.
It generates a deterministic, profile-specific representation policy, control checklist, and test plan while keeping preservation, validation, Unicode, container, metadata, provenance, capability, confirmation, output, evidence, and external-verification decisions separate. It never substitutes one universal “secure” preset for context-specific engineering judgment.
Choose no more than 5 profiles. Selecting more than one is useful because the resulting conflict record exposes where one universal rule would be destructive or misleading.
Each decision is rendered independently for every selected profile. Status labels describe intended treatment, not implementation evidence.
Whether the exact original bytes must be retained before decoding, normalization, sanitization, re-encoding, or canonical export.
How declared type, extension, magic bytes, character encoding, syntax, and structural boundaries are checked before processing.
Whether normalization is absent, diagnostic only, comparison-only, or part of a documented storage or protocol profile.
Whether identifier-specific script, character, bidi, skeleton, and collision rules apply to this representation.
Whether nested parts, object graphs, archive entries, MIME parts, chunks, relationships, revisions, or embedded resources must be inventoried inertly.
Which source, structural, rendered, semantic, extracted, tokenized, or behavioral planes must be compared before a conclusion or action.
How scripts, macros, actions, remote references, forms, links, tools, and other executable or state-changing features are blocked or sandboxed.
Which metadata fields are preserved as evidence, exposed to users, excluded from model input, or removed from a separately generated derivative.
How every selected field, transformation, fixture, parser, and output is linked to its source and processing history.
How untrusted representations are converted into a newly constructed, typed, provenance-labelled model input instead of raw concatenation.
Which read, write, network, tool, credential, memory, or execution capabilities are available to the component consuming the representation.
Which state-changing, external, financial, destructive, publishing, scheduling, or identity-sensitive actions require an explicit transaction preview and authorized approval.
How generated text, links, structured data, files, tool parameters, and UI output are checked before rendering, sharing, or execution.
Which source identities, transformations, parser versions, policy decisions, results, and exceptions must be retained—and which sensitive values must never be logged.
Which conclusions require an exact browser, parser, model, cryptographic service, DNS authority, registry, trust list, organizational owner, or legal/privacy authority.
The profile should implement this control as a default condition before the representation is trusted or acted upon.
The control normally improves resilience, reviewability, or evidence quality, but the exact implementation remains context-dependent.
The control may be appropriate only when the application, language, protocol, receiver, or authority explicitly requires it.
Applying this control in the described profile would silently destroy meaning, expose sensitive data, add an unsafe capability, or create a misleading trust claim.
The local policy can require and record this check, but an exact external authority or version-pinned implementation must establish the result.
The initial page produces no policy and performs no automatic analysis.
Select at least one profile above. Choose multiple profiles to reveal context conflicts.
A conflict is not an error. It identifies a place where one global setting would silently damage meaning, privacy, safety, or trust.
Generate a multi-profile policy to compare decision status across contexts.
Every item retains its source profile, decision, and status. Completing a checkbox in a printed copy does not establish independent assurance.
Generate a policy to create profile-specific implementation tasks.
The test plan tells an implementation team what local evidence to collect and when a conclusion must remain unresolved pending an external authority.
Generate a policy to produce deterministic test cases.
The builder resolves allowlisted profile rules and links them to existing evidence. It does not inspect a production system, verify a cryptographic claim, evaluate a model, contact a registry, resolve DNS, assess compliance, or decide whether a control is effective.