Morifar Decision Instrument
Morifar Decision Instrument
A transparent description of what the public demonstration does, what it cannot do, and how its claims should be interpreted.
1.4 · Calibrated governed-AI gateway
Explain how business intent can be mapped to evidence, control exposure and accountable authority.
Real risk classification, transaction approval, compliance advice or automated operational action.
Free-form text entered by the visitor. Do not enter personal, confidential, regulated or client information.
The default experience uses deterministic local mapping. Governed AI activates only when a private API key, explicit model, pseudonymous safety salt and durable rate-limit store are all configured. The interface labels AI and fallback modes separately.
Same-origin JSON requests, a 500-character boundary, request-size control, input moderation, pseudonymous safety identifiers, durable per-client rate limiting, a 20-second safe timeout, server-side schema validation and conservative control-exposure calibration.
The model must return the published decision-control-map/1.3 schema. Invalid, incomplete or out-of-range responses are rejected. Valid responses cannot undercut the declared-factor floor or the minimum band implied by their authority action.
Prompts and model outputs are not stored by Morifar. Model storage is disabled. Short-lived rate-limit counters retain only a salted hash, request count and expiry time; infrastructure providers may process ordinary security metadata.
Successful AI results expose a trace identifier, model, schema version, moderation state, output-validation state, calibration state, latency, storage position and external-action boundary.
Illustrative domain, evidence checklist, provisional control-exposure signal, authority route and trace stages.
The visitor initiates every trace. No external system action is available.
Simplified semantics, non-exhaustive policy logic, no jurisdictional rules and no independently validated outcome calibration. The conservative floor prevents understatement; it does not predict loss or prove compliance.
No authentication, client connector, upload or external tool permission. The database stores abuse-control counters only. Server credentials are never returned to the browser.
Morifar AI · Public experience team
13 July 2026