네 가지 핵심 원칙
Core Principles v2.0Version 2.0 · · Governance 2.0 public evidence surface
Governance 2.0 Overview
This page is part of the starnum public Governance 2.0 surface and uses the same evidence layer as the system card, data governance, transparency report, use policy, and security policy.
Governance Summary
This page states the operating principles that govern product, content, AI assistance, and public disclosure.
Scope
Cultural respect, autonomy, transparency, privacy, safety, accessibility, and evidence-backed release discipline.
Implementation Status
Version 2.0 turns the principles into a navigation hub connected to the same evidence layer as the policy pages.
이것이 starnum.com.tw의 운영 프레임워크입니다. 각 원칙에는 단순 선언이 아닌 구체적 기술 구현이 대응합니다.
마지막 업데이트:
구현된 기술 실행
- ✓방법론 페이지 (10 語言) — 지식 출처, 배반 엔진, 품질 프로세스의 완전한 설명
- ✓시스템 설명 카드(Model Card) — Starnum Logic Engine v5.0의 적용/비적용 범위, 알려진 한계
- ✓품질 벤치마크 — 37개 고정 명반 테스트 세트의 평가 결과, 정기 재실행 및 공개 비교
- ✓CHANGELOG 변경 이력 — 각 시스템 업데이트의 상세 기록, Keep a Changelog 형식 준수
- ✓유파 명시 — 전 사이트 陸斌兆 유파(중주파) 통일 채택, 유파 혼용 없음, model-card에 명시
- ✓한계 명시 — 사망 예측, 질병 진단, 정치인 분석 등 금지 영역을 acceptable-use 페이지에 공개
- ✓Claim-Evidence 시스템 — 각 글의 명리 주장에 지식 베이스 출처를 표기, 근거 없는 주장 배제
- ✓보안 공개 정책 — RFC 9116 표준, 30/60/90일 단계 복구 일정 공개
구현된 기술 실행
- ✓SHA256 콘텐츠 무결성 해시 — 각 글에 SHA256 값을 내장하여 JSON-LD
hasHash필드에 주입, 내용 변경 시 감지 가능 - ✓iztro 오픈소스 배반 엔진 — 배반 계산 로직이 완전히 오픈소스, 연구자는 명반 결과를 독립 검산 가능
- ✓JSON-LD Schema 기계 판독 — 각 글의 Schema는 자동 도구로 검증, schema.org 표준 준수
- ✓공개 벤치마크 세트 (eval-set) — 37개 고정 테스트 명반의 분석 기준 답안, 재현 검증 가능
- ✓Git 버전 이력 — 모든 내용 변경은 GitHub 공개 저장소에 보존, 모든 변경 추적 가능
- ✓117 條 명리 하드 규칙 자동 검증 — 글 발행 전 자동 대조, 규칙 위반 시 발행 차단
- ✓다중 모델 교차 검증 — 명리 로직을 4개 AI가 동시 대조, 어느 하나라도 이상 발견 시 재심 표시
- ✓의존성 취약점 스캔 — 로컬 도구가 정기적으로 npm 의존성을 스캔하여 서드파티 패키지 보안 확보
구현된 기술 실행
- ✓陸斌兆 유파 지식 베이스 — 2,758 檔 1,537,711+ 줄의 구조화 명리 텍스트, 8개 출처 교차 참조로 신뢰 가능한 문헌 기반 구축
- ✓유파 일관성 선언 — 전 사이트 중주파(陸斌兆) 사화표 통일, 지면 사정으로 유파 혼용하지 않음
- ✓고전 문헌 인용 — 중요 주장은 『紫微斗數全書』 시리즈 등 명명된 문헌 출처를 명시
- ✓4개 AI 합동 감사 — Anthropic / OpenAI / Google Gemini governance benchmarks가 명리 로직을 동시 심사, 투표로 수정 결정
- ✓117 條 명리 하드 규칙 — 사화 불가능 사건, 격국 판정 조건 등 핵심 규칙을 기계가 강제 실행
- ✓GraphRAG 지식 그래프 — 343 個實體節點 / 679 關係, 주장이 지식 구조에서 일관된 위치를 확보
- ✓저자 경력 명시 — 명리 연구 배경과 지식 체계 선택 이유를 about 페이지에 공개
- ✓22개 표준 분석 블록 — 각 명반 해설은 고정 구조로 작성, 분석의 완전성과 일관성을 보장
구현된 기술 실행
- ✓자동화 품질 워크플로 — 품질 검사, 사이트맵 업데이트, 인증서 만료 모니터링 등을 완전 자동 실행
- ✓규칙 생명 주기 관리 — 90일간 발동되지 않은 규칙은 자동 퇴출 후보화, 규칙 라이브러리 무한 팽창 방지
- ✓실패 기반 진화 — 동종 품질 문제가 3회 발생하면 자동으로 신규 규칙 제안, 동일 실수는 반복되지 않음
- ✓6층 품질 폐쇄 루프 (L1-L6) — 글 산출부터 전략층까지의 자동 품질 방어선, 층마다 인력 개입을 감소
- ✓콘텐츠 신선도 추적 — 기한 초과 글을 자동 감지하여 갱신 큐에 추가, 장기적 유효성 유지
- ✓리소스 상한 보호 — GPU lockfile로 메모리 오버플로 방지, 장시간 운영 안정성 확보
- ✓인증서 만료 추적 — API 키 및 서비스 인증서 만료 전 자동 경고, 서비스 중단 방지
- ✓저연산 비용 설계 — Cloudflare Pages 정적 배포 + Workers 엣지 연산, 운영 비용 통제
원칙이 충돌할 때의 판정
네 원칙이 충돌할 경우 다음 순서로 우선합니다:
P3 권위성 > P1 공개 투명성 > P2 검증 가능성 > P4 지속 가능성
즉: 내용 정확성(P3)을 낮추는 기능은 투명성(P1)이나 운영 효율(P4)을 높일 수 있더라도 배포하지 않습니다.
판정 사례
- P4 vs P3: 어떤 자동화 기능이 효율을 높이지만 명리 로직 오류를 도입할 수 있음 → P3 우선, 로직 검증 통과 전까지 배포하지 않음
- P1 vs P4: 일부 내부 데이터 공개로 투명성 상승, 그러나 추가 유지 보수 비용 발생 → P1 우선, 유지 비용은 당사 부담
- P2 vs P4: 검증 메커니즘 추가가 시스템 효율을 낮춤 → P2 우선, 검증은 건너뛸 수 없음
기능 × 원칙 대응 매트릭스
각 핵심 기능은 최소 2개 원칙에 대응해야 하며, 그렇지 않으면 필요성을 재평가합니다.
| 기능 | P1 투명 | P2 검증 | P3 권위 | P4 지속 |
|---|---|---|---|---|
| SHA256 콘텐츠 해시 | ✓ | ✓ | — | ✓ |
| Claim-Evidence 인용 시스템 | ✓ | ✓ | ✓ | — |
| 4개 AI 합동 감사 | ✓ | ✓ | ✓ | ✓ |
| 陸斌兆 유파 지식 베이스 (KB) | ✓ | ✓ | ✓ | ✓ |
| 117 條 명리 하드 규칙 | ✓ | ✓ | ✓ | ✓ |
| iztro 오픈소스 배반 엔진 | ✓ | ✓ | ✓ | — |
| 자동화 품질 워크플로 | — | ✓ | — | ✓ |
| 공개 벤치마크 (eval-set) | ✓ | ✓ | ✓ | — |
| 규칙 생명 주기 관리 | — | — | ✓ | ✓ |
관련 투명성 리소스
다음 리소스는 네 원칙이 각 층에서 어떻게 구현되는지 보여줍니다:
외부 표준 및 1차 자료
다음 1차 자료는 이 페이지의 판단 기준입니다. 비교 기준일 뿐 제3자가 이 사이트를 보증한다는 뜻은 아닙니다.
Current Machine Audit Snapshot
This block uses only traceable local audit data. No unsupported metrics or model claims are added.
- data/state-machine/i18n-parity.json: 8,036 parent URLs, 7,976 articles.
- data/kb-machine-audit.json: 3,238 source files, 0 missing coverage, 0 orphan chunks.
- data/discovery-surface-audit.json: 0 errors, 0 warnings.
- data/sla-report.json: critical / 5 critical, 0 warnings.
Content Maintenance And Update Decision
This block makes governance-page content machine-checkable: every page must disclose its source artifacts, related pages, and the gate that reports update needs.
Update Decision
This is not static copy. When source artifacts, related policies, public metrics, or generators change, AI Ops reports evidence and an AI agent decides whether the page needs edits.
Human Boundary
Systems detect, report, and preserve machine-readable evidence. Codex/Claude agents perform final judgment and repair.
Verification Command
node scripts/verify-trust-pages.js --check
data/state-machine/trust-pages.jsondata/public-claim-registry.jsondata/sla-report.json- Related governance pages: Ethics Statement · Privacy Policy · AI Safety · Accessibility
- Update flow:
npm run update:trust-pages→npm run test:trust
Verifiable Evidence Layer
This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.
| Claim ID | Verifiable value | Status | Owner | Source and verification |
|---|---|---|---|---|
| claim.public-url-manifest.indexable-count Public URL and canonical inventory |
38,965 indexable URLs | verified | sitewide | node scripts/generate-public-evidence-manifest.js --dry |
| claim.trust-pages.audit-pass-rate Trust page machine audit |
180/180 pass | verified | sitewide | node scripts/verify-trust-pages.js --check |
| claim.discovery-surface.zero-errors AI discovery surface audit |
{"errors":0,"warnings":0} | verified | sitewide | node scripts/verify-discovery-surface.js |
| claim.structured-data.jsonld-errors JSON-LD / structured data audit |
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} | verified | sitewide | node scripts/site-machine-audit.js |
| claim.status.sla-state Status page SLA source |
critical / 5 critical, 0 warnings | verified | sitewide | node scripts/generate-status-page.js |
| claim.provider-alignment.openai-anthropic-gemini OpenAI / Anthropic / Google Gemini benchmark alignment |
benchmark alignment only unless code/config evidence exists | verified | sitewide | node scripts/verify-public-evidence.js --check |
| claim.transparency-report.sha256 Transparency report SHA-256 anchor |
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} | verified | sitewide | node scripts/update-transparency-current-data.js |
| claim.release-integrity.gpg-signing GPG signing status |
GPG signing configured locally; GitHub verification pending | github_verification_pending | sitewide | gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature |
System Card V2.0: Technical Transparency Layer
This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.
Public architecture
Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.
AI-use disclosure
AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.
Quality and safety gates
Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.
Data traceability
Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.
| Governance area | OpenAI | Anthropic | Google Gemini | Starnum implementation evidence |
|---|---|---|---|---|
| Model/system-card disclosure | OpenAI models + safety docs | Claude model docs + system/model cards | Gemini model docs + safety settings | system-card, model-card, methodology, benchmark, transparency-log |
| Safety evaluation and use boundaries | Safety best practices / deployment checklist | Responsible Scaling / safety policy | Gemini safety controls / policy | AI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit |
| Data governance | Data controls / privacy controls | privacy and data handling docs | Gemini API data governance references | privacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes |
| Monitoring and release | production checklist / eval discipline | system-card transparency discipline | model/version documentation discipline | deploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits |
- Sources: data/state-machine/model-card.json, public-bench.json, trust-pages.json, security-headers.json.
- Sources: data/trust-pages-machine-audit.json, data/discovery-surface-audit.json, data/ai-answer-readiness-audit.json.
- Sources: data/kb-machine-audit.json, data/tm/quality-audit-report.json, data/sla-report.json.
- Official benchmark docs checked: 2026-07-30; links are listed in the OpenAI / Anthropic / Google Gemini alignment table.
The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.
Release Integrity And GPG
GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.
OpenAI / Anthropic / Google Gemini Alignment
The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-30
| Provider | Governance focus | Starnum disclosure | Official source |
|---|---|---|---|
| OpenAI | Model documentation, latest model notes, safety best practices, and data controls. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://platform.openai.com/docs/models |
| Anthropic | Claude model documentation, system/model cards, Responsible Scaling, and safety policy. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://docs.anthropic.com/en/docs/about-claude/models |
| Google Gemini | Gemini API model documentation, safety settings, data governance, and platform policy. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://ai.google.dev/gemini-api/docs/models |