# Evidence and governance charter

## Independence

Testing choices, wording and publication thresholds are not delegated to institutions, suppliers, funders or automated systems. Funding and material support are disclosed.

## Symmetry

The same evidence rules apply to favourable and unfavourable results. A consistent app is publishable. An unexplained connection is not automatically scandalous.

## Contestability

Every consequential claim receives a stable ID, scope, evidence class, limitation, response status, correction history and retest status.

## Corrections

- correct factual errors promptly;
- preserve a visible correction note;
- distinguish correction from later repair;
- do not silently rewrite the original test state;
- regenerate machine-readable records and hashes.

## Conflicts

Reviewers disclose employment, contracting, funding or close personal relationships with tested institutions and suppliers. A conflicted reviewer does not make the final publication decision.

## Automation

AI and automated tools may classify, cluster, extract and suggest. They may not independently publish:

- endpoint attribution;
- an accusation;
- a legal conclusion;
- a claim that a recipient received personal data;
- a verified repair.

## No league table

No aggregate privacy score, “worst app” ranking or red–green certification. Readers see specific relationships, service outcomes and uncertainties.

## Public-interest proportionality

The public value of a claim must exceed the privacy and security risk of publishing its supporting detail. Exact paths, headers or configurations may be withheld while the claim remains described at a safe level.
