RESPONSIBLE DEVELOPMENT
Trust starts with
clear boundaries.
These are working principles for an independent lab, not a certification or security audit. They set expectations for how capabilities, integrations, data handling, and limitations should be described.
Ideactivate builds software and explores AI-system designs. Trust comes from making boundaries visible: what the project does, what data or tools it touches, what it has not been tested against, and where a human remains responsible for judgment.
Describe capabilities precisely.
Documentation should distinguish shipped behavior from planned work. A planned sandbox is not an audited security boundary; a passing test suite is not proof of correctness; an MCP integration is not an endorsement or partnership with the model provider.
Keep the source of truth visible.
For Atrium, repository files remain authoritative over indexes or remembered facts. Structured context can be useful, but parsing, indexing, and stored notes can be incomplete or stale. Any tool that changes code should leave the developer able to inspect the underlying diff and local checks.
Prefer explicit permissions and inspectable actions.
Tools that run commands, access files, or execute extensions need clear scope and visible outcomes. The user should understand which action is being requested, what permissions it requires, and how to review the result. Sandboxing and process isolation are design questions that require threat modeling and testing, not labels that automatically confer safety.
Do not equate model output with verification.
A model may propose a plausible explanation or patch while missing an edge case. Compilation, tests, static analysis, and human review each provide different kinds of evidence; none alone covers every failure mode. Atrium's verification path is intended to return engineering feedback, not to certify a change as correct.
Be clear about integrations and affiliations.
Atrium's MCP integration path is intended for Claude Code and other compatible coding clients. Ideactivate is independent and is not an Anthropic product, partner, or endorsed organization. Any mention of a third-party tool describes a technical integration, not a business relationship.
Make data handling part of the design.
Local-first storage reduces the need to send project metadata to a separate hosted service, but it does not by itself guarantee privacy or security. Users should review the code, dependencies, network behavior, and permissions before using experimental developer tools with sensitive repositories. Do not assume any project has undergone a security audit unless an audit is explicitly documented.
Correct the record when the work changes.
As the implementation evolves, project status, setup instructions, and evaluation claims should be updated. If a claim cannot be reproduced, it should be qualified or removed rather than retained because it sounds impressive.