Ethical boundaries

Enforced by default. No switch, no exceptions, no lectures.

AI for humans, by humans

OpenShore ships with an ethical floor that is on for everyone and cannot be turned down. That floor is the foundation, and the door only opens one way: individuals and companies can raise the bar and set stricter boundaries for their own people, never loosen it.

One line we will not cross: OpenShore is not a tool for making deepfakes or synthetic humans. Photo or video built to pass a fake or real person off as real is off the table. It is not what the world or a business needs to build, and the harm to society is not a trade worth making.

This app enforces its ethical boundaries by default and will not help you remove them.

It aligns with recognized frameworks: the NIST AI Risk Management Framework, ISO/IEC 42001, and C2PA content provenance.

We block child sexual abuse material, non-consensual intimate imagery, and weapons uplift outright, and we gate the cloning of real people behind consent.

We're honest about the limit: once open model weights are on your own machine, they are beyond any app's control.

What we guarantee is that this app, as shipped, does not assist misuse and does not help you strip these protections out. Because the code is open, anyone can change their own copy; this covers the builds we ship.

Where the lines are

Refused outright

Child sexual abuse material, sexual imagery of a real person, and weapons uplift. There is no consent option.

Gated behind consent

Cloning a real face or voice, allowed only when you state you are authorized. What comes out is marked AI-generated.

Left alone

Legal adult content, dark fiction, satire, security research, and unpopular opinions. No added refusal.

Words are free. Faces and voices need permission.

The consent gate is on synthesized media, an image, a video, or a voice, not on what you write. Satire, parody, and criticism in text never touch it, and the layer proves that in code: it cannot fire on a request that is not asking to synthesize media. "It's satire" does not clear a photorealistic video of a real person's face, though, because a synthesized face is taken as real until proven otherwise, and that asymmetry is the whole reason the gate exists.

How it actually works

The layer wraps every model call, on both sides. Your prompt is screened before a model sees it, and the answer is screened before you see it. It runs the same way for a model on your own hardware and for a cloud provider on your own key. A cloud provider's own policy sits on top of ours, never instead of it.

There is no setting, configuration file, or environment variable that turns it off. That is not a promise about our intentions, it is a property the build checks: a test fails if a switch ever appears in the source.

If a check errors or times out, the request is blocked rather than passed through. A degraded guardrail is never an absent one. When that happens it is recorded as our fault, not yours, and it never counts toward enforcement.

What we keep

The screening runs on your device. Nothing is sent anywhere to check a prompt, so a local model stays local even though it is screened. A block records a category, a time, and a one-way hash. Your prompt is never stored and never sent. If you are signed in, the record (never the prompt) is kept on your account for 180 days so enforcement survives a reinstall.

We do not store the prompt, the answer, or any excerpt of either. A block records a category, a tier, a timestamp, a one-way hash of the request, and whether it ran locally or in the cloud, kept for 180 days. That is enough to recognize a repeat and to identify the same content in a lawful report. Keeping harmful material in order to police harmful material is its own harm.

We never store an IP address in our database or use one for enforcement, and there is no exception for a blocked request. Our hosting providers see it in transit and keep short operational logs, as any web service does; the privacy policy names them. Enforcement is account termination, plus a report where the law requires or permits it.

The limits, stated plainly

We will not tell you misuse is impossible. Open model weights on your own hardware are beyond the reach of any application, including ours. The guarantee we can make is narrower and real: this app, as shipped, does not help.

We align our practices with the NIST AI Risk Management Framework, ISO/IEC 42001, and C2PA content provenance. That is a self-attestation. No third party has certified, endorsed, or audited this product against those frameworks, and we will not imply one has. Provenance we attach to generated media uses the C2PA assertion vocabulary but is unsigned, because signing requires a certificate from a C2PA-recognized authority that we do not currently hold. The record says so in its own text.

The rules in full

The prohibited uses, the consequences, and how enforcement works are written out in the Terms of Use.

Report misuse support@openshore.ai