Skip to main content

Security

Dobby Security

jhf-dobby is the Fabric-governed adaptive-learning module for Helpifyr. It produces recommendation and learning posture, but it must not become an unreviewed authority for external actions, tenant-crossing synthesis, policy changes, or source-code mutation.

Security Boundaries

  • Dobby must fail closed to warmup, observe_only, or proposal_only when Fabric truth, approval integrity, policy integrity, or tenant separation is missing.
  • No-learn zones are hard boundaries and must not be bypassed by replay, promotion, or recommendation flows.
  • Learning output is advisory unless an admitted owner workflow explicitly promotes it.
  • Dobby must not mutate external repositories, workflow files, source files, or production systems directly.
  • Sensitive evidence should be linked by owner reference, not copied into public docs, Gitea comments, logs, or generated recommendation text.
  • Runtime diagnostics must be bounded and must not leak secrets, tokens, credentials, tenant data, or private trace payloads.

Public Documentation Safety

Public manufacturer docs may describe Dobby's advisory role, tenant separation, no-learn posture, and verification paths. They must not expose private learning records, raw traces, tenant-specific samples, or operator-only evidence.

Verify Path

  • python scripts/validate_docs_inventory.py
  • python scripts/validate_docs_platform_v1_6.py
  • python scripts/validate_module_docs.py

License

AGPLv3. See LICENSE. Project: https://helpifyr.com