Trust

The best verdict an email can get is incomplete

Outlook, Gmail and Apple Mail rendering cannot be reproduced locally, so one gate says could not measure, and Nucleus will not round that up to a pass. Each guarantee below names what holds it.

  • A gate that could not measure is never counted as a pass
  • Every gate's reason is written next to it
  • The gate that cannot measure names what a person must check before sending

Verdict

an email, at its best

incomplete

13 gates, in the order they run

  • 12 pass
  • 1 could not measure
email.client-rendercould not measure

Outlook (Word engine), Gmail and Apple Mail rendering cannot be reproduced locally. Check the email in real clients, or a rendering service, before it is sent.

Before it is sent, a person must check

  • Outlook for Windows (the Word rendering engine)
  • Gmail on the web and in its apps, including a non-Gmail account (which drops <style> entirely)
  • Apple Mail on macOS and iOS
  • Every client with images blocked
  • The plain-text part in a text-only client
The engine's 13 email gates, in the order they run. When the 12 that can run locally pass, the verdict is incomplete, because email.client-render can never pass locally.
13
Email gates
The gates an email is checked against, in the order they run
12
Measured locally
Every email gate but the one that cannot be reproduced locally
1
Never passes locally
The gate that cannot measure, and the verdict says so
3
Outcomes a gate can give
Pass, fail and could not measure
The rule

Pass means every gate passed. Nothing else does.

Every gate answers pass, fail or could not measure. The verdict is then one of three words, by one rule, applied in one order.

  • A page that hangs, spins or runs out of memory while it is checked fails
  • Any other error a gate throws is recorded as could not measure
  • An answer the engine cannot read is recorded as could not measure

The verdict rule

in the order the engine applies it

  1. If any gate failedfail
  2. Else, if every gate passedpass
  3. Anything else, a could not measure includedincomplete
The engine's verdict rule, in words. A status it does not recognise counts as incomplete too, never as a pass.
Why believe us

Every promise here names what holds it

Most are held by code that a test runs. One is held by a written decision, and its card says so.

  • A gate that could not measure is never a pass

    Outlook's rendering, at the top of this page, is the example.

    Held by
    The verdict rule, and the tests that run it.
  • You pick. No model ranks the directions.

    Directions are checked for being different, never ranked. Each shows the brand risks noted by the model that proposed it. A review's record holds the pick you made.

    Held by
    The review record, which stores the pick a person made, and a check for difference that keeps directions in the order they came.
  • Nucleus does not train on your data

    Not on your briefs, picks, comments or approvals.

    Held by
    A written decision, not a check.
  • Every preview runs on a host apart from the app

    Sandboxed, sent with no cookie, and refused every fetch and form post by its own policy.

    See the headers
    Held by
    Its response headers, a hostile page tested in real Chrome, and, in production, an app that frames previews from that host alone.
  • Your SOW and PRD stay in your tenant

    Isolated to your tenant, and no external model reads them. Your brief and brand kit are read by the external model that makes the designs.

    See a refusal
    Held by
    The tenant on your session, and a check on the document's class before any model is called.
  • Not claimed

    What we do not claim

    • A security certification. Nucleus holds none today, so none is shown.
    • Customer names, logos or numbers. Nucleus is not open yet.
    • A render check in Outlook, Gmail or Apple Mail. That gate says could not measure.
    Status
    Not true today, so not said.
Previews

A design can run. It cannot read your session.

Every preview is treated as a stranger's code, whoever wrote it. It is served from a preview host apart from the app and from this site, behind a signed link that expires. Its scripts run, so the motion is real, and its policy refuses every fetch and form post.

  • Fetches, form posts and pop-ups are refused
  • No cookies: a preview response never sets one
  • Its own origin, even when the link is opened on its own

Response headers

every preview is served with these

content-security-policy
  • sandbox allow-scripts;
  • default-src 'none';
  • script-src 'unsafe-inline';
  • style-src 'unsafe-inline';
  • img-src data:;
  • font-src data:;
  • media-src data:;
  • connect-src 'none';
  • frame-src 'none';
  • object-src 'none';
  • form-action 'none';
  • base-uri 'none';
  • frame-ancestors (the app's origin)
x-content-type-options
nosniff
cache-control
no-store
cross-origin-resource-policy
same-site
cross-origin-opener-policy
same-origin
referrer-policy
no-referrer
set-cookie
never sent
The preview host's header contract. frame-ancestors names the app's origin: only the app may frame a preview.
Your documents

No external model reads your SOW or PRD

A statement of work carries prices and legal terms. It stays isolated to your tenant, and no model reads it today. The check runs before a request is made, so a refused document is never sent.

  • Your tenant comes from your session. A request cannot name another
  • A SOW or a PRD is always sensitive, by its type
  • Asking a model to propose requirements from a SOW or a PRD is refused before the call

Refused before sending

the document's class, checked against the model's

sample refusal
Document
SOW (illustrative)
Data class
sensitive
Model cleared for
general
Outcome
refused before any call

What the check returns

{ cleared: false, requested: "sensitive", clearedFor: ["general"] }
The shape the data-class check returns inside Nucleus, and the words its refusal opens with. Every value here is illustrative.
Questions

Straight answers about trust

Do you train on my data?
No. Nucleus does not train on your data: not on your briefs, picks, comments or approvals. That promise rests on a written decision, not on a check, and this page says so.
Why is an email's best verdict incomplete?
An email is checked against 13 gates, and 12 of them can be measured locally. The last, rendering in Outlook, Gmail and Apple Mail, cannot be reproduced locally, so it says could not measure. A could not measure is never counted as a pass: if no gate failed, the verdict is incomplete (a failed gate still makes it fail), and the gate lists what a person should check in real clients before the email is sent.
Can a preview read my session?
No. A preview is served from a preview host apart from the app, in an origin of its own even when its link is opened on its own, so it cannot read the app's cookies or the page it is shown in. A preview response never sets a cookie, and its policy refuses every fetch and form post.
Who reads my SOW and PRD?
A person. No model reads one today: a SOW or a PRD is always sensitive, no model is cleared for sensitive data, and the check on a document's class runs before any model is called.
Who decides which design is best?
You do. Directions are checked for being different from each other, never ranked, and no model picks one. Each shows the brand risks noted by the model that proposed it. A review's record holds the pick you made.
Do you hold a security certification?
Not today, so this page shows none.

Know what was checked, and what could not be

Nucleus is not open yet.