Notarizing documentation

Privacy and accessibility

Developer preview. Not yet production ready. This page is rendered from docs/privacy-and-accessibility.md of the Notarizing repository at revision d23579e737f9d1e16e07b3c6b21a51282d64027e. It describes the behavior of that revision.

Contents

This page states what notarizing sends over the network, what it stores, and which accessibility checks ran. It describes this revision. Section 60 of n0-decisions.md records how the statements were checked.

Privacy

No telemetry

Notarizing has no telemetry, no usage statistics, no crash reports, no update check and no analytics. It does not contact the project or any hosted service. The browser interface loads every asset from the binary. Its Content-Security-Policy allows only the origin of serve.

Network connections

Notarizing makes only these connections:

ConnectionWhenDestination
Browser servernotarizing serveListens on 127.0.0.1:<port>. It refuses a request whose Host header is not exactly that address.
Control APIserve listens; other CLI commands connect127.0.0.1 on a random port, named in control.json of the workspace. The client dials only that loopback address, uses no proxy and follows no redirect.
Ollama embeddingsOnly after search provider setA literal loopback address, for example http://127.0.0.1:11434. A host name or another address is refused. No proxy, no redirect.
ka2a adapterOnly with serve --ka2a-config FILEThe Kafka brokers that the file names, through the ka2a module.

Other process starts:

  • Notarizing runs git to read registered repositories. Every Git transport protocol is off, so git cannot fetch.
  • serve --open asks the system to open the loopback address in a browser.

The offline browser test (TestRealBrowserOffline) and make qualify-clean run the product in a network namespace with only a loopback interface.

What the workspace stores

The workspace database holds what you import: repository paths, the source text of imported changes, check reports and artifacts, review records with their display labels, search indexes and, with the Ollama provider, vectors of the source text. It is not encrypted. Its file permissions protect it (directory 0700, files 0600).

Logs do not hold request bodies, search queries, source text or secrets.

Where your data can go

  • An MCP client gets the text that its tools return. If the agent sends that text to a hosted model, the text leaves your host. Notarizing cannot control this. Configure the agent as your data policy requires.
  • The ka2a adapter answers change.report requests of bound producers with the requested report.
  • A backup, a bundle, a review export or a graph export is a file that you control. A purge does not reach copies that you made before it.

Accessibility

The browser interface aims to support keyboard use, zoom, reduced motion and sufficient contrast. It claims no conformance level. The ledger rows N-043-A and N-043-B in the acceptance ledger hold the evidence.

Tested

These tests run with Playwright in Chromium against the packaged binary (make browser-test-real):

  • Keyboard only: the main review tasks on this repository's change. This includes moving through rows with Tab and the arrow keys with visible focus, opening and closing the inspector, the table view of the graph, finding an assumption by its exact ID, and the export dialog up to the download.
  • 200 % zoom: Review, the inspector and Explore at 720 x 450 CSS pixels, which is a 1440 x 900 screen at 200 %. There is no horizontal page scroll, and graph labels are at least 12 CSS pixels.
  • Reduced motion: no transition and no graph animation when the browser asks for reduced motion.
  • Automated checks: axe finds no violation, color contrast included, in Review, the inspector, Explore, Compare, Search and Export, in the light and the dark theme.

Not tested

  • No screen reader was tested. The interface has labels for assistive technology, but nobody has checked them with NVDA, JAWS, VoiceOver or Orca.
  • No browser other than Chromium was tested.
  • Operating-system high-contrast modes, voice control and switch access were not tested.
  • No test checks that every status has text in addition to color. The design asks for it.
  • No user study with people with disabilities was done.

Report an accessibility problem as a bug. Use the bug report template.

All Notarizing documents