AI Guard protects text before an approved AI request. Standard access is per signed browser session; Priority Invite is per issued invite, not per person. Both service classes have the same safety, review, parser, approval, and output gates.
One application, two service classes
Standard access
Starts a fixed 30-minute signed browser session. The reviewed caps are 6 ordinary text requests/minute, 1 document request/minute, and 1 queue join/minute per signed Standard session; global lanes still apply. It has no artificial one-run total cap.
Priority Invite
Uses an issued high-entropy credential. The reviewed caps are 30 ordinary text requests/minute, 4 document requests/minute, and 6 queue joins/minute per issued Priority session; global lanes still apply. It is not administrative access and never reveals logs, secrets, mappings, configuration, or other sessions.
Retry only the explicitly named completed action. Do not retry an uncertain provider request: reload reads queue status only and never restores private payload or execution authority. Use the synthetic example entry in the application for a controlled example. This reference page makes no API call and contains no live text playground.
Supported scope and privacy path
Exact HTTP contract
Hosted 3.0.2 has 40 exact same-origin locations: 20 canonical paths plus their exact /v1 aliases. They comprise health/auth/detect/guard/roundtrip/report paths and Standard start/end, preview/execute, document, and provider-queue operations. Prefix, wildcard, implicit-version, /v2, /v3, unknown methods, query-bearing control calls, internal routes, PDF redaction, and OCR routes are denied.
New additive operations require HTTP contract version 2 at the organizer/API boundary. Responses use deterministic value-free error envelopes, request IDs where a completed operation creates one, Cache-Control: no-store, and server-authored timing metadata. Health is liveness only: it does not state provider readiness.
Retry truth
Retry only the action named by the response. Never repeat an uncertain provider request: the application allows one unresolved provider-bound operation per authority and displays status rather than claiming a resend.
Rates
Reviewed values are service-class and global safeguards, not throughput promises. Standard and Priority share parser/output correctness gates; Core remains authoritative for session, queue, and per-issued-invite enforcement.
Starting rates and deterministic errors
These are Hosted 3.0.2 ceilings, not an uptime or throughput promise. Core owns verified-session and per-issued-invite limits; Nginx also applies global transport limits.
Fixed error and recovery groups
401 authentication_required returns to access. Approval and queue errors require either the named preview retry or authority restart. Document 422 errors distinguish unsupported structure, missing text layer, excessive visual content, and complexity without reflecting parser detail. 429 covers rate, queue, or parser capacity. Provider/configuration/timeout/integrity/restoration failures return value-free fixed codes and never expose an unsafe or partially restored result. Early Nginx 413/429 responses intentionally have no Core timing headers.
Approval and queue
Journey: prepare → preview the exact protected payload → explicit approval → queue → matching claim → automatic execute → verified result. The page must stay open and in the foreground. Visibility loss, offline state, app switching, minimization, or phone lock pauses eligibility before selection while keeping fairness age; it does not stop the server deadline. If an issued automatic-start claim misses its handoff, the first miss moves the request to the queue tail and the second expires it without provider contact. Refresh recovers status only, never private payload or execution authority.
Queue position is approximate, no ETA is promised, and the absolute deadline derives from a server-time sample anchored to performance.now(), never device wall clock. Missing, malformed, delayed, skewed, BFCache-restored, or resumed timing anchors fail closed before provider contact.
Evidence and limits
The locked evaluation uses 138 constructed Thai PII cases plus a separate 32-case Section 26 heuristic set. On that exact constructed corpus, exact typed precision was 76.86%, recall 77.50%, F1 77.18%, and protective-character recall 91.57%. It is deterministic synthetic/adversarial evidence, not a population-representative benchmark, not proof of perfect detection, and not a legal/compliance accuracy claim. API/proxy tests cover exact routes, deterministic errors, rate limits, session/authority, queue claims, portable artifacts, and privacy boundaries; browser and public production acceptance are separate evidence layers.
The repository does not establish a public legal operator, jurisdiction, or private public security inbox. Do not submit secrets, cookies, invite codes, raw sources, or provider payloads in public reports. For safe reproducible source issues, use the project’s documented support path.