Contract purpose
The contract kit translates the reports’ private-ordering logic into operational commitments. It does not create certification or legal advice. It gives builders and users a precise language for custody, transformation, refusal, and export.
Every clause should preserve the core rule: originals remain originals; derivatives are marked; boundary decisions are logged outside the source.
Core clauses
| Clause | Plain meaning | Artifact |
|---|
| Source Preservation | Provider preserves the deposited source as immutable. | Source preservation manifest. |
| Derivative Rule | Authorized changes become labeled derivatives. | Derivative provenance manifest. |
| Boundary Separation | Runtime limits happen outside the source. | Boundary event log. |
| No Hidden Steering | No undisclosed vulnerability or sentiment profiling to manipulate choices. | Mental privacy consent manifest. |
| Fidelity Warranty | Service labels must match published variance thresholds. | Persona fidelity record. |
| Portability | User receives sources, derivatives, logs, and metadata in usable formats. | Export packet. |
Sample warranty language
Provider warrants that any service labeled “identity-preserving,” “high-fidelity,” “source-faithful,” or similar will materially conform to the fidelity metrics and variance thresholds disclosed in the applicable service schedule.
If Provider cannot render a Source Persona faithfully, Provider must disclose the variance, preserve the source unchanged, and either decline execution or create an explicitly labeled derivative.
Remedies ladder
Restore
Return the preserved source to the last verified hash.
Export
Deliver source, derivatives, provenance, consent, event logs, and metadata.
Correct
Repair inaccurate variance reports or false fidelity claims.
Compensate
Use contract, warranty, arbitration, or anti-fraud remedies for material breach.
Machine-readable companion
The package adds `persona-custody-contract.schema.json` and an example record for contract-backed source custody. It is deliberately narrow: no private data, no targets, no operational harm instructions.