Security · privacy · accessibility · assurance

Trust starts with limits you can see.

We keep design intent, implemented source controls, test evidence, product qualification, release authority, and availability separate. This page explains the current website controls and the application roadmap. Product availability requires a separate decision.

Current boundaries

What the site supports—and what it does not prove.

Security

The site keeps a small browser surface, restrictive response policy, bounded dependencies, and a private pilot-interest form with validated fields. It offers no visitor accounts, file uploads, payments, or product downloads. These source controls are not a security certification or a guarantee against every threat.

Privacy

Pilot interest is stored privately with withdrawal and deletion controls. Separate daily activity totals contain no form contents or visitor identifiers. There is no account creation, advertising, visitor profiling, or third-party analytics SDK. Calm mode stores one on/off preference in this browser. Hosting infrastructure may still process ordinary request, session, and security metadata needed to deliver and protect the site.

Accessibility

The source includes semantic landmarks, keyboard-operable native controls, visible focus styles, responsive layouts, reduced-motion behavior, forced-colors adjustments, and Calm mode. A public launch also requires independent assistive-technology, contrast, text-spacing, 200%/400% zoom, and real-device review; source controls alone are not conformance evidence.

Responsible intelligence

Planned application workflows may assist with observation, organization, and bounded interpretation. It must not hide material uncertainty, infer a personal diagnosis or crisis state, manufacture authority, or perform irreversible protected actions without consent.

Public-launch readiness

One visible view of every gate.

The main website is published; that does not establish product availability or completion of the reviews below. “Pending” means the required external evidence or accountable decision is absent; source code cannot close it.

  1. 01

    Website implementation

    Source, routes, launch controls, and production build are checked in the current candidate scope.

    Candidate validated
  2. 02

    Product qualification

    Each application requires its own qualification evidence and release decision. Trace still requires authorized native Windows qualification.

    Pending
  3. 03

    Identity and legal review

    Name clearance, operator presentation, domain control, and production identity approval require external evidence.

    Pending
  4. 04

    Visitor care

    The privacy notice and owner-designated vulnerability-reporting email are published. General product support, service hours, and response-time commitments remain unverified.

    Partially active
  5. 05

    Operations

    Monitoring, incident ownership, backup and rollback evidence, protected delivery, and post-deployment checks remain launch gates.

    Pending
  6. 06

    Website publication and search

    The public website uses www.thirteenfoldsystems.com. The owner authorized search discovery for its informational pages on 08 September 2026. Private intake-management pages remain excluded. Application downloads, sales, qualification, and product release require separate decisions.

    Authorized

Status glossary

Plain language for the states on this site.

Proposed direction
A role being considered for the roadmap. Its name and implementation remain under review; it is not an available product.
Specified only
A defined application plan or architecture exists; the label does not establish an implemented product.
Internal candidate
An implementation is reported internally. Its qualification and release authority must be assessed separately.
Internal candidate reported
A bounded implementation has been reported in the private record; this public snapshot does not independently qualify it.
Qualification pending
The required native environment and owner-approved procedure have not yet produced a release decision.
Release authority closed
No test, repository state, or website update can authorize distribution on its own.
Private discovery only
The current work is problem and workflow validation—not a public product offer.

Security reporting · active

Report a website security issue.

Email Thirteenfoldsystems@gmail.com with the affected URL or hostname, a short impact description, reproducible steps, and the least sensitive evidence needed to understand the issue. Use the subject “Security report: short description.”

Do not include passwords, access tokens, private management links, personal records, client data, or harmful payloads. If sensitive evidence is necessary, send a general summary first and ask for transfer instructions. Email is not presented as end-to-end encrypted. Do not access other people’s data, disrupt service, maintain access, or test beyond what is necessary to explain the issue.

This email is for security reports about public Thirteenfold website surfaces. It is not an emergency channel, product help desk, or bug-bounty program. Receipt, response time, remediation, public acknowledgment, and reward are not promised. General product support remains inactive while products are unavailable.

Read the security.txt contact record