Expand capability扩展能力
Intelligence should give a person more ways to understand, decide and act.
智能应该让人拥有更多理解、判断与行动的方式。
CAELARIUM · TRUST CENTERCAELARIUM · 信任中心
CAELARIUM builds intelligent systems to expand human capability without diminishing human agency. Trust begins with clear boundaries: what a system can access, what it can remember, what it can do, and who remains in control.
CAELARIUM 希望用智能系统扩展人的能力,而不是削弱人的自主权。信任首先来自清晰的边界:系统能够访问什么、记住什么、执行什么,以及最终由谁掌握控制权。
This page describes CAELARIUM's current design principles and the data handling of the present preview stage. It does not claim certifications, controls or production infrastructure that do not yet exist.
本页说明 CAELARIUM 当前已经确定的设计原则,以及现阶段预览版本中的数据处理方式。尚不存在的认证、安全控制或生产基础设施不会被提前宣称为已经完成。
THE PERSON REMAINS THE CENTER人始终处于中心
Intelligence should give a person more ways to understand, decide and act.
智能应该让人拥有更多理解、判断与行动的方式。
The person keeps the goals, values and final authority over meaningful choices.
人的目标、价值判断与重要选择的最终决定权应继续属于本人。
A person's digital self is not automatically a platform asset because the software was built by CAELARIUM.
不能因为软件由 CAELARIUM 制造,就默认一个人的数字自我属于平台。
LOCAL-FIRST本地优先
L.I.A. is being developed around a local-first direction: personal context and intelligence should remain on user-controlled devices when that is practical and consistent with the feature the person asked for.
L.I.A. 正沿着本地优先方向开发:在功能允许且符合用户请求的情况下,个人上下文与智能能力应尽可能运行和保留在用户可控制的设备上。
Local-first does not mean every future service can never use a server. When a feature genuinely requires remote infrastructure, that dependency and the data involved should be made clear.
“本地优先”不等于未来任何功能都绝不能使用服务器。若某项能力确实需要远程基础设施,应明确说明依赖关系以及涉及的数据。
WHAT IS TRUE TODAY今天真实存在的处理方式
The current Early Access and Business Inquiry forms collect only the information a visitor chooses to submit, such as name, work email, company and inquiry context.
当前 Early Access 与 Business Inquiry 表单只收集访问者主动填写的信息,例如姓名、工作邮箱、公司以及咨询背景。
The form explicitly asks visitors not to submit customer records, passwords, health information, financial account data or other sensitive personal data.
表单明确要求不要提交客户记录、密码、健康信息、金融账户数据或其他敏感个人信息。
In the current local preview workflow, an inquiry is stored by the local preview server and a notification can be sent to the configured CAELARIUM Gmail inbox. Production handling will be documented before public launch.
在当前本地预览流程中,咨询由本地预览服务器保存,并可向已配置的 CAELARIUM Gmail 收件箱发送通知。正式公开上线前会重新明确生产环境的数据处理方式。
MEMORY记忆
Long-term memory can make intelligence more continuous and useful. That does not make the memory CAELARIUM's property. The long-term direction is for people to have meaningful control over what is remembered and retained.
长期记忆可以让智能更加连续、更有用,但这并不意味着这些记忆因此属于 CAELARIUM。长期方向是让用户对“系统记住什么、保留什么”拥有真正的控制能力。
These are product requirements for the L.I.A. direction. Availability will be documented release by release; this page does not imply every memory control is already shipped.这些是 L.I.A. 长期产品方向中的要求。具体能力会随版本逐步说明;本页并不代表所有记忆控制功能现在都已经发布。
L.I.A. RECALL · BUSINESS DATA
L.I.A. Recall is currently being built around stale quote recovery for local service businesses. The present intake asks for business context — not the underlying customer database.
L.I.A. Recall 当前围绕本地服务企业的历史未成交报价追回进行构建。现阶段申请入口询问的是业务背景,而不是要求企业上传底层客户数据库。
Future production integrations will need product-specific data handling and security documentation before they are presented as ready.未来如果接入生产级企业系统,需要在公开宣称可用之前补充针对具体产品的数据处理和安全说明。
SECURITY安全
CAELARIUM will not use certifications, encryption labels or security language as decoration before the underlying controls exist. The current preview includes a small set of real safeguards that can be stated precisely.
在底层控制真正存在之前,CAELARIUM 不会把认证、加密标签或安全术语当作装饰。当前预览版本只说明已经真实存在、能够准确描述的少量保护措施。
The Gmail App Password used for local testing is not placed in public HTML or JavaScript.
本地测试使用的 Gmail App Password 不会写入公开 HTML 或 JavaScript。
On the current Windows preview setup, the email credential is stored with Windows DPAPI for the current Windows user.
在当前 Windows 预览环境中,邮件凭据通过 Windows DPAPI 为当前 Windows 用户加密保存。
The local preview server blocks browser access to the private .caelarium_runtime directory where inquiry records and local configuration are stored.
本地预览服务器会阻止浏览器访问保存咨询记录和本地配置的私有 .caelarium_runtime 目录。
The current inquiry endpoint uses request-size limits, field validation, a honeypot field and basic rate limiting.
当前咨询接口包含请求大小限制、字段校验、Honeypot 隐藏字段和基础频率限制。
CAELARIUM does not currently present SOC 2, ISO 27001, production end-to-end encryption, a formal security audit or other uncompleted controls as finished. Formal Privacy Policy, Terms and production security documentation will be finalized before public v1.0 deployment.
CAELARIUM 当前不会把 SOC 2、ISO 27001、生产级端到端加密、正式安全审计或其他尚未完成的控制描述成已经具备。正式 Privacy Policy、Terms 与生产环境安全说明将在 v1.0 公开部署前结合真实数据流完成。
FUTURE SENSITIVE DATA未来高敏感数据
CAELARIUM's long-term frontier may include health and neurotechnology. Those are future directions, not current products. If the company enters them, health and neural data should require stronger standards of informed authorization, security, purpose limitation and revocability.
CAELARIUM 的长期前沿方向可能包括健康科技与神经科技,但它们不是当前已经存在的产品。未来真正进入这些领域时,健康与神经数据应采用更高标准的知情授权、安全保护、用途限制与可撤销性。
Neural data is part of the person.神经数据是人的一部分。
WHAT CAELARIUM WILL NOT NORMALIZECAELARIUM 不会把这些做法视为理所当然
A person's identity, memory and sensitive life context should not become company property merely because a CAELARIUM system processed it.
一个人的身份、记忆和敏感生活背景,不应仅仅因为被 CAELARIUM 系统处理过就变成公司资产。
Automation should not quietly turn convenience into permanent control over a person's choices.
自动化不应把“方便”悄悄变成对个人选择的永久控制。
Security badges and claims should follow real controls, not lead them.
安全标识和宣传应该建立在真实控制之后,而不是走在工程之前。
PRIVACY & DATA QUESTIONS隐私与数据问题
During the current pre-launch stage, privacy and data questions can be sent to CAELARIUM's temporary company inbox. A dedicated domain privacy address will replace it when caelariumhq.com is deployed.
在当前正式上线前阶段,隐私与数据问题可以发送到 CAELARIUM 的临时公司邮箱。等 caelariumhq.com 正式部署后,会更换为独立的域名隐私邮箱。