Direct answer
Privacy Boundary — Served Bundle Check is implemented as a source-bounded served bundle check guide.
Answer contract
Apply the served bundle check lens only to the exact inspected source scope; do not infer authority from adjacent topics.
Evidence and exact locators
Digest-gated served-bundle privacy scanner and adversarial fixture — lib/batch-11-evidence-verifier.ts — scanForProhibitedContent; test/batch-11-scanner-path-awareness.test.ts — the exemption is a single exact literal at a single exact path. Supports: Scans a digest-verified output for credential shapes and named private-data classes while allowing one exact static policy literal at one exact path.
What the evidence does not establish
A passing scan covers the implemented patterns and inspected bundle; it does not prove absence of every possible confidential datum or authorize publication.
Rights and reuse
project-owned-reference-only
Dependencies and related concepts
applies-to: urn:maha:concept:evidence:privacy-boundary
governed-by: urn:maha:concept:governance
evidence-for: urn:maha:concept:evidence
Executable contract
This executable contract section is constrained to the same inspected scope: Scans a digest-verified output for credential shapes and named private-data classes while allowing one exact static policy literal at one exact path.
It must preserve the recorded boundary: A passing scan covers the implemented patterns and inspected bundle; it does not prove absence of every possible confidential datum or authorize publication.
Verification evidence
This verification evidence section is constrained to the same inspected scope: Scans a digest-verified output for credential shapes and named private-data classes while allowing one exact static policy literal at one exact path.
It must preserve the recorded boundary: A passing scan covers the implemented patterns and inspected bundle; it does not prove absence of every possible confidential datum or authorize publication.
Failure boundaries
This failure boundaries section is constrained to the same inspected scope: Scans a digest-verified output for credential shapes and named private-data classes while allowing one exact static policy literal at one exact path.
It must preserve the recorded boundary: A passing scan covers the implemented patterns and inspected bundle; it does not prove absence of every possible confidential datum or authorize publication.
Dependencies
This dependencies section is constrained to the same inspected scope: Scans a digest-verified output for credential shapes and named private-data classes while allowing one exact static policy literal at one exact path.
It must preserve the recorded boundary: A passing scan covers the implemented patterns and inspected bundle; it does not prove absence of every possible confidential datum or authorize publication.
Questions this page can answer
What is implemented?
Privacy Boundary — Served Bundle Check is implemented as a source-bounded served bundle check guide.
Which exact locator proves it?
Digest-gated served-bundle privacy scanner and adversarial fixture, lib/batch-11-evidence-verifier.ts — scanForProhibitedContent; test/batch-11-scanner-path-awareness.test.ts — the exemption is a single exact literal at a single exact path
What fails closed?
A passing scan covers the implemented patterns and inspected bundle; it does not prove absence of every possible confidential datum or authorize publication.
What does the implementation not establish?
applies-to: urn:maha:concept:evidence:privacy-boundary governed-by: urn:maha:concept:governance evidence-for: urn:maha:concept:evidence
Which release gates remain?
A source, locator, rights, scope, boundary, dependency, implementation, or release change requires a new exact-revision review.