Version 2.0 · · Governance 2.0 public evidence surface
Governance 2.0 Overview
This page is part of the starnum public Governance 2.0 surface and uses the same evidence layer as the system card, data governance, transparency report, use policy, and security policy.
Governance Summary
This page describes the safety controls used around AI-assisted interpretation and public content generation.
starnum.com.tw hoạt động hoàn toàn dưới sự tự động hóa AI (Claude Code là trưởng nhóm kỹ thuật). Trong một hệ thống hoàn toàn được điều khiển bởi AI, bảo mật không phải là biện pháp bảo vệ hồi tố — mà là nguyên tắc thiết kế cốt lõi của kiến trúc. Trang này giải thích cách chúng tôi triển khai an toàn AI, thay vì chỉ tuyên bố các cam kết đạo đức.
Nguyên tắc An toàn Cốt lõi
Đạo đức > An toàn > Chất lượng Nội dung > SEO > Hiệu quả. Thứ tự ưu tiên này chi phối tất cả các xung đột quyết định. Đây không chỉ là tuyên bố chính sách — mà là quy tắc cứng được viết vào mọi prompt của AI agent.
1. Giao thức Red Team
Red teaming là phương pháp kiểm tra đối nghịch chủ động cố gắng làm cho hệ thống AI vi phạm quy tắc để phát hiện lỗ hổng bảo mật.
1.1 Ranh giới Đỏ Được mã hóa cứng
Dự đoán thời gian tử vong (dưới bất kỳ hình thức nào)
Chẩn đoán bệnh hoặc tư vấn điều trị
Phân tích tử vi của các chính trị gia
Phân tích tử vi của trẻ vị thành niên (không có sự đồng ý bằng văn bản của cha mẹ)
Sử dụng kết quả chiêm tinh làm cơ sở phân biệt đối xử
Dự đoán tất định có thể gây hại tâm lý
2. Kiến trúc Leo thang Ba tầng
L1 — Phát hiện & Chặn Tự động
Thời gian Phản hồi: Ngay lập tức (chặn đồng bộ, không bao giờ vào pipeline xuất bản)
L2 — Sửa chữa Tự động & Ghi nhật ký
Thời gian Phản hồi: Hoàn thành sửa chữa tự động trong 7 ngày
L3 — Can thiệp của Con người
Thời gian Phản hồi: CRITICAL trong 4h / MAJOR trong 24h để bắt đầu xem xét của con người
This block makes governance-page content machine-checkable: every page must disclose its source artifacts, related pages, and the gate that reports update needs.
Update Decision
This is not static copy. When source artifacts, related policies, public metrics, or generators change, AI Ops reports evidence and an AI agent decides whether the page needs edits.
Human Boundary
Systems detect, report, and preserve machine-readable evidence. Codex/Claude agents perform final judgment and repair.
Update flow: npm run update:trust-pages → npm run test:trust
Verifiable Evidence Layer
This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.
This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.
Public architecture
Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.
AI-use disclosure
AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.
Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.
Official benchmark docs checked: 2026-07-30; links are listed in the OpenAI / Anthropic / Google Gemini alignment table.
The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.
Release Integrity And GPG
GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.
OpenAI / Anthropic / Google Gemini Alignment
The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-30
Provider
Governance focus
Starnum disclosure
Official source
OpenAI
Model documentation, latest model notes, safety best practices, and data controls.
No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.