The best verdict an email can get is incomplete
Outlook, Gmail and Apple Mail rendering cannot be reproduced locally, so one gate says could not measure, and Nucleus will not round that up to a pass. Each guarantee below names what holds it.
Verdict
an email, at its best
13 gates, in the order they run
- 12 pass
- 1 could not measure
email.client-rendercould not measureOutlook (Word engine), Gmail and Apple Mail rendering cannot be reproduced locally. Check the email in real clients, or a rendering service, before it is sent.
Before it is sent, a person must check
- Outlook for Windows (the Word rendering engine)
- Gmail on the web and in its apps, including a non-Gmail account (which drops <style> entirely)
- Apple Mail on macOS and iOS
- Every client with images blocked
- The plain-text part in a text-only client
Pass means every gate passed. Nothing else does.
Every gate answers pass, fail or could not measure. The verdict is then one of three words, by one rule, applied in one order.
- A page that hangs, spins or runs out of memory while it is checked fails
- Any other error a gate throws is recorded as could not measure
- An answer the engine cannot read is recorded as could not measure
The verdict rule
in the order the engine applies it
- If any gate failedfail
- Else, if every gate passedpass
- Anything else, a could not measure includedincomplete
Every promise here names what holds it
Most are held by code that a test runs. One is held by a written decision, and its card says so.
A gate that could not measure is never a pass
Outlook's rendering, at the top of this page, is the example.
- Held by
- The verdict rule, and the tests that run it.
You pick. No model ranks the directions.
Directions are checked for being different, never ranked. Each shows the brand risks noted by the model that proposed it. A review's record holds the pick you made.
- Held by
- The review record, which stores the pick a person made, and a check for difference that keeps directions in the order they came.
Nucleus does not train on your data
Not on your briefs, picks, comments or approvals.
- Held by
- A written decision, not a check.
Every preview runs on a host apart from the app
Sandboxed, sent with no cookie, and refused every fetch and form post by its own policy.
See the headers- Held by
- Its response headers, a hostile page tested in real Chrome, and, in production, an app that frames previews from that host alone.
Your SOW and PRD stay in your tenant
Isolated to your tenant, and no external model reads them. Your brief and brand kit are read by the external model that makes the designs.
See a refusal- Held by
- The tenant on your session, and a check on the document's class before any model is called.
- Not claimed
What we do not claim
- A security certification. Nucleus holds none today, so none is shown.
- Customer names, logos or numbers. Nucleus is not open yet.
- A render check in Outlook, Gmail or Apple Mail. That gate says could not measure.
- Status
- Not true today, so not said.
A design can run. It cannot read your session.
Every preview is treated as a stranger's code, whoever wrote it. It is served from a preview host apart from the app and from this site, behind a signed link that expires. Its scripts run, so the motion is real, and its policy refuses every fetch and form post.
- Fetches, form posts and pop-ups are refused
- No cookies: a preview response never sets one
- Its own origin, even when the link is opened on its own
Response headers
every preview is served with these
- content-security-policy
sandbox allow-scripts;default-src 'none';script-src 'unsafe-inline';style-src 'unsafe-inline';img-src data:;font-src data:;media-src data:;connect-src 'none';frame-src 'none';object-src 'none';form-action 'none';base-uri 'none';frame-ancestors(the app's origin)
- x-content-type-options
- nosniff
- cache-control
- no-store
- cross-origin-resource-policy
- same-site
- cross-origin-opener-policy
- same-origin
- referrer-policy
- no-referrer
- set-cookie
- never sent
No external model reads your SOW or PRD
A statement of work carries prices and legal terms. It stays isolated to your tenant, and no model reads it today. The check runs before a request is made, so a refused document is never sent.
- Your tenant comes from your session. A request cannot name another
- A SOW or a PRD is always sensitive, by its type
- Asking a model to propose requirements from a SOW or a PRD is refused before the call
Refused before sending
the document's class, checked against the model's
- Document
- SOW (illustrative)
- Data class
sensitive- Model cleared for
general- Outcome
- refused before any call
What the check returns
{ cleared: false, requested: "sensitive", clearedFor: ["general"] }