SYSTEM CARD / SC-001

Morifar Decision Instrument

A transparent description of what the public demonstration does, what it cannot do, and how its claims should be interpreted.

PRINT-READY DOCUMENT
System

Morifar Decision Instrument

Version

1.4 · Calibrated governed-AI gateway

Intended use

Explain how business intent can be mapped to evidence, control exposure and accountable authority.

Prohibited use

Real risk classification, transaction approval, compliance advice or automated operational action.

Inputs

Free-form text entered by the visitor. Do not enter personal, confidential, regulated or client information.

Intelligence method

The default experience uses deterministic local mapping. Governed AI activates only when a private API key, explicit model, pseudonymous safety salt and durable rate-limit store are all configured. The interface labels AI and fallback modes separately.

Gateway controls

Same-origin JSON requests, a 500-character boundary, request-size control, input moderation, pseudonymous safety identifiers, durable per-client rate limiting, a 20-second safe timeout, server-side schema validation and conservative control-exposure calibration.

Output contract

The model must return the published decision-control-map/1.3 schema. Invalid, incomplete or out-of-range responses are rejected. Valid responses cannot undercut the declared-factor floor or the minimum band implied by their authority action.

Retention boundary

Prompts and model outputs are not stored by Morifar. Model storage is disabled. Short-lived rate-limit counters retain only a salted hash, request count and expiry time; infrastructure providers may process ordinary security metadata.

Trace evidence

Successful AI results expose a trace identifier, model, schema version, moderation state, output-validation state, calibration state, latency, storage position and external-action boundary.

Outputs

Illustrative domain, evidence checklist, provisional control-exposure signal, authority route and trace stages.

Human oversight

The visitor initiates every trace. No external system action is available.

Known limitations

Simplified semantics, non-exhaustive policy logic, no jurisdictional rules and no independently validated outcome calibration. The conservative floor prevents understatement; it does not predict loss or prove compliance.

Security boundary

No authentication, client connector, upload or external tool permission. The database stores abuse-control counters only. Server credentials are never returned to the browser.

Evidence owner

Morifar AI · Public experience team

Review date

13 July 2026