StateHinge

Security model

Trust the boundary you can inspect.

StateHinge does not promise perfect safety. It narrows what a run is allowed to do, requires declared checks before acceptance, and keeps a record of the decision and recovery path.

Scoped project boundaryFailed checks block acceptanceHuman approval is explicitRecovery is verified

Current verified controls.

Scope stays bounded

Product profiles cannot silently switch the project root or weaken the pinned safety policy in the verified core.

Validation is a gate

Failed deterministic validation blocks mutation of accepted project state in the verified core.

Recovery is checked

The verified core includes rollback restoration and current-file/baseline hash evidence.

Data and credentials

Keep sensitive data out of the sales flow.

Do not email secrets or production credentials. The current launch scope is intentionally bounded, and the first workflow should be chosen so verification and recovery can be demonstrated without broad production access.

What this page does not claim

Live business does not mean every integration or environment is verified.

Named coding-agent integrations, clean external-machine onboarding, and broader operating-system or production-repository support are only claimed when the relevant evidence is closed. See the dated Limitations page for the current boundary.

Before you install

Read the limitations, then test one bounded workflow.