Notarizing documentation
Privacy and accessibility
Developer preview. Not yet production ready. This page is rendered from docs/privacy-and-accessibility.md of the Notarizing repository at revision d23579e737f9d1e16e07b3c6b21a51282d64027e. It describes the behavior of that revision.
Contents
This page states what notarizing sends over the network, what it stores, and which accessibility checks ran. It describes this revision. Section 60 of n0-decisions.md records how the statements were checked.
Privacy
No telemetry
Notarizing has no telemetry, no usage statistics, no crash reports, no update check and no
analytics. It does not contact the project or any hosted service. The browser interface
loads every asset from the binary. Its Content-Security-Policy allows only the origin of
serve.
Network connections
Notarizing makes only these connections:
| Connection | When | Destination |
|---|---|---|
| Browser server | notarizing serve | Listens on 127.0.0.1:<port>. It refuses a request whose Host header is not exactly that address. |
| Control API | serve listens; other CLI commands connect | 127.0.0.1 on a random port, named in control.json of the workspace. The client dials only that loopback address, uses no proxy and follows no redirect. |
| Ollama embeddings | Only after search provider set | A literal loopback address, for example http://127.0.0.1:11434. A host name or another address is refused. No proxy, no redirect. |
| ka2a adapter | Only with serve --ka2a-config FILE | The Kafka brokers that the file names, through the ka2a module. |
Other process starts:
- Notarizing runs
gitto read registered repositories. Every Git transport protocol is off, sogitcannot fetch. serve --openasks the system to open the loopback address in a browser.
The offline browser test (TestRealBrowserOffline) and make qualify-clean run the product
in a network namespace with only a loopback interface.
What the workspace stores
The workspace database holds what you import: repository paths, the source text of imported changes, check reports and artifacts, review records with their display labels, search indexes and, with the Ollama provider, vectors of the source text. It is not encrypted. Its file permissions protect it (directory 0700, files 0600).
Logs do not hold request bodies, search queries, source text or secrets.
Where your data can go
- An MCP client gets the text that its tools return. If the agent sends that text to a hosted model, the text leaves your host. Notarizing cannot control this. Configure the agent as your data policy requires.
- The ka2a adapter answers
change.reportrequests of bound producers with the requested report. - A backup, a bundle, a review export or a graph export is a file that you control. A purge does not reach copies that you made before it.
Accessibility
The browser interface aims to support keyboard use, zoom, reduced motion and sufficient contrast. It claims no conformance level. The ledger rows N-043-A and N-043-B in the acceptance ledger hold the evidence.
Tested
These tests run with Playwright in Chromium against the packaged binary
(make browser-test-real):
- Keyboard only: the main review tasks on this repository's change. This includes moving through rows with Tab and the arrow keys with visible focus, opening and closing the inspector, the table view of the graph, finding an assumption by its exact ID, and the export dialog up to the download.
- 200 % zoom: Review, the inspector and Explore at 720 x 450 CSS pixels, which is a 1440 x 900 screen at 200 %. There is no horizontal page scroll, and graph labels are at least 12 CSS pixels.
- Reduced motion: no transition and no graph animation when the browser asks for reduced motion.
- Automated checks: axe finds no violation, color contrast included, in Review, the inspector, Explore, Compare, Search and Export, in the light and the dark theme.
Not tested
- No screen reader was tested. The interface has labels for assistive technology, but nobody has checked them with NVDA, JAWS, VoiceOver or Orca.
- No browser other than Chromium was tested.
- Operating-system high-contrast modes, voice control and switch access were not tested.
- No test checks that every status has text in addition to color. The design asks for it.
- No user study with people with disabilities was done.
Report an accessibility problem as a bug. Use the bug report template.