Scope stays bounded
Product profiles cannot silently switch the project root or weaken the pinned safety policy in the verified core.
Security model
StateHinge does not promise perfect safety. It narrows what a run is allowed to do, requires declared checks before acceptance, and keeps a record of the decision and recovery path.
Product profiles cannot silently switch the project root or weaken the pinned safety policy in the verified core.
Failed deterministic validation blocks mutation of accepted project state in the verified core.
The verified core includes rollback restoration and current-file/baseline hash evidence.
Data and credentials
Do not email secrets or production credentials. The current launch scope is intentionally bounded, and the first workflow should be chosen so verification and recovery can be demonstrated without broad production access.
What this page does not claim
Named coding-agent integrations, clean external-machine onboarding, and broader operating-system or production-repository support are only claimed when the relevant evidence is closed. See the dated Limitations page for the current boundary.
Before you install