Back to CAELARIUM返回 CAELARIUM
CAELARIUM

CAELARIUM · TRUST CENTERCAELARIUM · 信任中心

Your intelligence.
Your capability.
Your data.
你的智能。
你的能力。
你的数据。

CAELARIUM builds intelligent systems to expand human capability without diminishing human agency. Trust begins with clear boundaries: what a system can access, what it can remember, what it can do, and who remains in control.

CAELARIUM 希望用智能系统扩展人的能力,而不是削弱人的自主权。信任首先来自清晰的边界:系统能够访问什么、记住什么、执行什么,以及最终由谁掌握控制权。

CURRENT PRINCIPLES · PRE-LAUNCH当前原则 · 正式上线前

This page describes CAELARIUM's current design principles and the data handling of the present preview stage. It does not claim certifications, controls or production infrastructure that do not yet exist.

本页说明 CAELARIUM 当前已经确定的设计原则,以及现阶段预览版本中的数据处理方式。尚不存在的认证、安全控制或生产基础设施不会被提前宣称为已经完成。

THE PERSON REMAINS THE CENTER人始终处于中心

Technology should increase your choices — not quietly replace them.技术应该增加选择,而不是替你选择。

01

Expand capability扩展能力

Intelligence should give a person more ways to understand, decide and act.

智能应该让人拥有更多理解、判断与行动的方式。

02

Preserve agency保留自主权

The person keeps the goals, values and final authority over meaningful choices.

人的目标、价值判断与重要选择的最终决定权应继续属于本人。

03

Keep ownership clear明确数据归属

A person's digital self is not automatically a platform asset because the software was built by CAELARIUM.

不能因为软件由 CAELARIUM 制造,就默认一个人的数字自我属于平台。

01

LOCAL-FIRST本地优先

Keep personal intelligence close when it can be.能留在身边的个人智能,尽量留在身边。

L.I.A. is being developed around a local-first direction: personal context and intelligence should remain on user-controlled devices when that is practical and consistent with the feature the person asked for.

L.I.A. 正沿着本地优先方向开发:在功能允许且符合用户请求的情况下,个人上下文与智能能力应尽可能运行和保留在用户可控制的设备上。

A boundary, not a slogan.这是架构边界,不是营销口号。

Local-first does not mean every future service can never use a server. When a feature genuinely requires remote infrastructure, that dependency and the data involved should be made clear.

“本地优先”不等于未来任何功能都绝不能使用服务器。若某项能力确实需要远程基础设施,应明确说明依赖关系以及涉及的数据。

WHAT IS TRUE TODAY今天真实存在的处理方式

The current website collects less by design.当前官网有意少收集数据。

Inquiry forms咨询表单

The current Early Access and Business Inquiry forms collect only the information a visitor chooses to submit, such as name, work email, company and inquiry context.

当前 Early Access 与 Business Inquiry 表单只收集访问者主动填写的信息,例如姓名、工作邮箱、公司以及咨询背景。

Sensitive data敏感数据

The form explicitly asks visitors not to submit customer records, passwords, health information, financial account data or other sensitive personal data.

表单明确要求不要提交客户记录、密码、健康信息、金融账户数据或其他敏感个人信息。

Preview-stage handling预览阶段处理

In the current local preview workflow, an inquiry is stored by the local preview server and a notification can be sent to the configured CAELARIUM Gmail inbox. Production handling will be documented before public launch.

在当前本地预览流程中,咨询由本地预览服务器保存,并可向已配置的 CAELARIUM Gmail 收件箱发送通知。正式公开上线前会重新明确生产环境的数据处理方式。

02

MEMORY记忆

Memory is part of a person's digital self.记忆是一个人数字自我的一部分。

Long-term memory can make intelligence more continuous and useful. That does not make the memory CAELARIUM's property. The long-term direction is for people to have meaningful control over what is remembered and retained.

长期记忆可以让智能更加连续、更有用,但这并不意味着这些记忆因此属于 CAELARIUM。长期方向是让用户对“系统记住什么、保留什么”拥有真正的控制能力。

  • View what is remembered.查看被记住的内容。
  • Correct or remove memories that should not remain.修改或删除不应继续保留的记忆。
  • Make retention and transfer understandable.让保留与迁移规则能够被用户理解。

These are product requirements for the L.I.A. direction. Availability will be documented release by release; this page does not imply every memory control is already shipped.这些是 L.I.A. 长期产品方向中的要求。具体能力会随版本逐步说明;本页并不代表所有记忆控制功能现在都已经发布。

PERMISSION BEFORE ACTION行动之前先明确权限

Intelligence can assist. Authority should stay explicit.智能可以协助,但权力必须保持明确。

01Understand

Understand the context, intent, uncertainty and risk.先理解背景、真实意图、不确定性与风险。

02Empower

Provide knowledge, options and tools that restore the power to act.提供知识、选择与工具,让人重新拥有行动能力。

03Act Together

Execute only within clear permission and bounded capability.只在明确授权和能力边界内共同执行。

04Protect When Necessary

Warn or interrupt clear, urgent danger without turning protection into permanent control.面对明确且紧迫的危险可以警告或阻止,但保护不能变成永久夺取控制权。

03

L.I.A. RECALL · BUSINESS DATA

Business intelligence still needs boundaries.企业智能同样需要边界。

L.I.A. Recall is currently being built around stale quote recovery for local service businesses. The present intake asks for business context — not the underlying customer database.

L.I.A. Recall 当前围绕本地服务企业的历史未成交报价追回进行构建。现阶段申请入口询问的是业务背景,而不是要求企业上传底层客户数据库。

Current intake may include当前申请可能包含Name · work email · company · optional website · market · business context · message姓名 · 工作邮箱 · 公司 · 可选官网 · 市场 · 业务背景 · 留言
Do not send through the current form当前表单不要提交Customer records · passwords · health information · financial account data · other sensitive personal data客户记录 · 密码 · 健康信息 · 金融账户数据 · 其他敏感个人信息

Future production integrations will need product-specific data handling and security documentation before they are presented as ready.未来如果接入生产级企业系统,需要在公开宣称可用之前补充针对具体产品的数据处理和安全说明。

SECURITY安全

Security claims must be earned.安全,必须由真实工程获得。

CAELARIUM will not use certifications, encryption labels or security language as decoration before the underlying controls exist. The current preview includes a small set of real safeguards that can be stated precisely.

在底层控制真正存在之前,CAELARIUM 不会把认证、加密标签或安全术语当作装饰。当前预览版本只说明已经真实存在、能够准确描述的少量保护措施。

CURRENT

Secrets stay server-side凭据留在服务端

The Gmail App Password used for local testing is not placed in public HTML or JavaScript.

本地测试使用的 Gmail App Password 不会写入公开 HTML 或 JavaScript。

CURRENT

Local secret protection本地凭据保护

On the current Windows preview setup, the email credential is stored with Windows DPAPI for the current Windows user.

在当前 Windows 预览环境中,邮件凭据通过 Windows DPAPI 为当前 Windows 用户加密保存。

CURRENT

Runtime data is not public运行数据不公开

The local preview server blocks browser access to the private .caelarium_runtime directory where inquiry records and local configuration are stored.

本地预览服务器会阻止浏览器访问保存咨询记录和本地配置的私有 .caelarium_runtime 目录。

CURRENT

Basic intake defenses基础提交防护

The current inquiry endpoint uses request-size limits, field validation, a honeypot field and basic rate limiting.

当前咨询接口包含请求大小限制、字段校验、Honeypot 隐藏字段和基础频率限制。

FUTURE SENSITIVE DATA未来高敏感数据

The closer technology gets to the person, the higher the standard should become.技术越接近人,保护标准就越高。

CAELARIUM's long-term frontier may include health and neurotechnology. Those are future directions, not current products. If the company enters them, health and neural data should require stronger standards of informed authorization, security, purpose limitation and revocability.

CAELARIUM 的长期前沿方向可能包括健康科技与神经科技,但它们不是当前已经存在的产品。未来真正进入这些领域时,健康与神经数据应采用更高标准的知情授权、安全保护、用途限制与可撤销性。

Neural data is part of the person.神经数据是人的一部分。

WHAT CAELARIUM WILL NOT NORMALIZECAELARIUM 不会把这些做法视为理所当然

Digital self as platform property把数字自我当作平台资产

A person's identity, memory and sensitive life context should not become company property merely because a CAELARIUM system processed it.

一个人的身份、记忆和敏感生活背景,不应仅仅因为被 CAELARIUM 系统处理过就变成公司资产。

Hidden authority隐形夺取决定权

Automation should not quietly turn convenience into permanent control over a person's choices.

自动化不应把“方便”悄悄变成对个人选择的永久控制。

Security theater安全表演

Security badges and claims should follow real controls, not lead them.

安全标识和宣传应该建立在真实控制之后,而不是走在工程之前。

PRIVACY & DATA QUESTIONS隐私与数据问题

Ask before you have to guess.如果有疑问,直接问我们。

During the current pre-launch stage, privacy and data questions can be sent to CAELARIUM's temporary company inbox. A dedicated domain privacy address will replace it when caelariumhq.com is deployed.

在当前正式上线前阶段,隐私与数据问题可以发送到 CAELARIUM 的临时公司邮箱。等 caelariumhq.com 正式部署后,会更换为独立的域名隐私邮箱。

Current privacy contact当前隐私联系邮箱 caelarium@gmail.com Planned at v1.0: privacy@caelariumhq.comv1.0 计划:privacy@caelariumhq.com