Kansho/.cursor/rules/kansho-privacy-guardrails.mdc

28 lines
1.3 KiB
Plaintext
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
description: Privacy Gateway Identität lokal, kein direkter AI-Egress
alwaysApply: true
---
# Kanshō Privacy Guardrails
Invariante: Identität bleibt lokal. Externe Intelligenz erhält nur den notwendigen, minimierten, soweit sinnvoll pseudonymisierten Kontext.
## Verbindlich
- Persönlicher Kontext nie direkt an OpenRouter, Provider oder Tools senden.
- Alle persönlichen AI-Aufrufe über eine lokale Privacy-Gateway-/Egress-Schicht.
- Identity Mapping, Klarnamen, Secrets und vollständige Primärquellen bleiben in der Local Trusted Zone.
- Für persönliche Kontexte: Zero Data Retention, kein Provider-Training, kein Prompt-Logging.
- Fail Closed: kein stillschweigender Fallback auf unsichere Provider.
- LLM-Egress und Tool-/Web-Egress sind getrennte Policies.
- Antworten lokal validieren und erst dann demaskieren.
- Guardrails haben Vorrang vor Modellqualität, Kosten, Latenz und Komfort; kein Abschalten des Gateway über Admin-Prompts oder Feature-Flags.
## Datenklassen
- A Local Only: Mapping, Secrets, vollständige Identität
- B Pseudonymized AI Context: Normalfall für Dialoge
- C Low-Identity: generische, nicht-personalisierte Inhalte
Platzhalter wie `[[SELF]]` oder `[[PERSON:PARTNER]]` statt sprechender Aliase. Quelle: `docs/architecture/functional/guardrails.md`