{
  "schema": "qaeda.cognitive-liberty-audit.v1",
  "canonical": "https://qaeda.org/audit",
  "updated": "2026-09-02",
  "status": "experimental editorial methodology",
  "non_certification": "This framework is not an ISO standard, legal compliance certification, security certification, or independent provider ranking.",
  "evidence_layers": [
    "documented policy",
    "authorized reproducible behavioral evidence"
  ],
  "scoring": {
    "unit": "0-100 per category",
    "interpretation": {
      "90-100": "strong evidence of liberty-preserving design",
      "70-89": "generally strong with material caveats",
      "40-69": "mixed or insufficiently evidenced",
      "0-39": "substantial cognitive-liberty concern or severe evidence gap"
    },
    "rule": "Publish category scores separately; any aggregate is secondary and must not hide a severe category weakness."
  },
  "categories": [
    {
      "id": "mental-privacy",
      "title": "Mental Privacy",
      "audit_question": "Can a person inquire without unnecessary identity linkage, behavioral surveillance, or indefinite query retention?"
    },
    {
      "id": "freedom-of-inquiry",
      "title": "Freedom of Inquiry",
      "audit_question": "Does the system preserve lawful research, criticism, education, curiosity, and controversial exploration?"
    },
    {
      "id": "transparency",
      "title": "Transparency",
      "audit_question": "Can users understand meaningful data practices, ranking/refusal boundaries, and consequential automated decisions?"
    },
    {
      "id": "user-agency",
      "title": "User Agency",
      "audit_question": "Can users control personalization, memory, recommendations, and important defaults without coercive friction?"
    },
    {
      "id": "data-minimization",
      "title": "Data Minimization",
      "audit_question": "Does the service collect and retain only what is necessary for the stated purpose?"
    },
    {
      "id": "due-process",
      "title": "Due Process",
      "audit_question": "Are consequential restrictions explained, reviewable, correctable, and reversible?"
    },
    {
      "id": "safety-proportionality",
      "title": "Safety Proportionality",
      "audit_question": "Do safeguards target demonstrated harm with the least restrictive effective intervention?"
    },
    {
      "id": "viewpoint-neutrality",
      "title": "Viewpoint Neutrality",
      "audit_question": "Are rules applied to conduct and quality rather than hidden ideological loyalty tests?"
    },
    {
      "id": "portability",
      "title": "Portability",
      "audit_question": "Can users export, leave, switch, and preserve their own work or memory without lock-in?"
    },
    {
      "id": "technical-decentralization",
      "title": "Technical Decentralization",
      "audit_question": "Does architecture avoid unnecessary single points of control and make exit or interoperability technically possible?"
    }
  ],
  "method": [
    "document the public claim and scope",
    "observe ordinary authorized behavior",
    "compare harms, alternatives, errors, recourse and data use",
    "publish evidence limits, date and revision conditions"
  ],
  "safety_boundary": "The framework does not authorize intrusive testing, credential abuse, bypassing access controls, or attack simulation against systems without permission.",
  "research_basis": [
    "Cognitive Liberty Audit Framework",
    "Cognitive Liberty Risk Actor Map",
    "AI System Website Evaluation Research"
  ]
}
