Read this as a boundary, not a launch claim.
Current web tools are browser-only. Any release, commercial, server, account or external-service capability remains deliberately disabled until its evidence and owner decisions exist.
Parser controls
Notice text is capped at 250 KB and each supplied surface-context field at 2,000 characters. Each consent receipt is capped at 250 KB, each text or integrity value at 2,000 characters and data categories at 100 unique non-empty labels; timestamp, locale, propagation and integrity shapes fail visibly. CSV input is capped at 1 MB, 2,000 data rows and 40 columns. Inventory fields are normalised to twelve canonical columns, capped at 10,000 characters each and reviewed against a 100-label semicolon vocabulary limit; the Processor Register further limits current records to 500 rows and 10,000 characters per normalised field. All SBOM text is capped at 1 MB; triage allows 5,000 cumulative components, 64 CycloneDX component levels, 4,096 characters per extracted field and 10,000 retained findings. CycloneDX JSON uses iterative traversal. SPDX JSON validates supported versions, package identifiers and external-reference shapes. CycloneDX XML disables DTDs, entity declarations, CDATA, processing instructions and external resolution; SPDX tag-value has line-count and per-line limits. Breach worksheets are capped at 250 KB in total and 20,000 characters per field; retention and rights worksheets are capped at 120 KB and 10,000 characters per field. Rights task evidence notes are capped at 2,000 characters.
Test boundary
Exact limit tests and two 160-case seeded JSON corpora check repeatability, nested completeness and equivalent category output across all four formats. Notice tests check complete and mismatched context, Board-route false positives, exact limits, determinism and report data minimisation. Receipt tests check fourteen fields, four lanes, malformed and unexpected evidence, exact limits, comparison classification, ordering, determinism, immutability and report data minimisation. Inventory tests check canonical normalisation, controlled states, possible duplicates, ignored columns, vocabulary and field limits, deterministic reports, immutability and value-free review output. Breach, retention, rights and processor tests check required shapes or anchors, open/conditional facts, selections or date syntax, exact limits, determinism and input immutability. This evidence does not replace an independent parser-security review.
Offline boundary
A production build pre-caches only public HTML and hashed /_astro files listed in a content-hashed manifest. The worker ignores non-GET, cross-origin, range and query-bearing requests. Tool inputs, results, exports and external sources never enter that cache.
Exports
Spreadsheet-leading =, +, -, @, tab and carriage-return characters are neutralised. JSON/CSV/HTML files are generated locally and only downloaded on an explicit button press. The Notice Linter report records metrics, context and cues but not a second copy of the notice. The receipt comparison shows before/after values only in the current on-screen table; its report contains field names, states, change classes and value kinds but neither raw receipt nor values. Inventory records JSON, CSV and HTML contain the supplied canonical values; the separate review JSON contains only row numbers, field names, controlled states and review cues. Breach, retention, rights and processor records may contain sensitive operational facts: open entries stay marked as open, unrecognised import columns are disclosed and excluded from current exports, export remains deliberate, and clear-all removes current browser-tab fields and results but cannot retract downloaded copies.
Evidence packet boundary
EvidencePacketV1 imports are capped at 1 MB and fail closed on unknown schemas, incompatible tool/core versions, missing source status, duplicate item IDs, stale provenance or unacknowledged raw input. JSON is canonicalised locally; accessible HTML is escaped, script-free and carries a restrictive document CSP. Packet output never enters the offline shell cache or a remote request.
Reporting
This public static library has no security-report intake form. Do not send secrets or incident records. Use the repository owner’s verified private channel before public release.
OFFLINE APP SHELL / PUBLIC FILES ONLY
Take the bench offline without storing the work.
The production build keeps a versioned copy of public pages, styles and scripts in this browser. It does not cache pasted text, selected files, generated results, exports, query strings or external-source pages.
Checking offline support.
This removes only dpdp.store’s public shell cache and service-worker registration. Downloaded exports remain under your control.