# ngram safety, legal disclaimers, and operating boundaries

> ngram connects generative models to persistent memory, communication channels, local and remote execution tools, and embodied spatial surfaces. Operators are solely responsible for permissions, model providers, network exposure, supervision, and all operational outcomes.

## Mandatory operating posture

- Deploy strictly under the principle of **least privilege**.
- Enable only the tools and filesystem roots an Entity requires.
- Keep credentials in git-ignored environment configuration files or secure hardware secret stores.
- Restrict messaging bot identities with platform access controls and allowlists.
- Audit autonomous wake routines and scheduled tasks prior to unattended operation.
- Treat external tools and Model Context Protocol (MCP) servers as privileged code execution surfaces.

## Security architecture and credentials

Hosted inference credentials must remain server-side behind the runtime gateway. Network interfaces, WebSocket bridges, and spatial daemon endpoints require cryptographic token authentication, schema-validated payloads, and rate limiting.

Normal local and hosted execution requires no public network exposure. Quest LAN mode must only be operated across verified, trusted private networks. Any remote gateway deployment must be protected by access controls, TLS, and scoped service credentials. Do not expose gateways or debug interfaces to public networks.

## Autonomous execution and tool safety

When enabled by the operator, tools possess the capability to read, write, modify, or delete local filesystem records, execute arbitrary shell commands, invoke external APIs, initiate financial transactions, and transmit outbound messages across connected platforms.

**Assumption of Risk:** The operator assumes sole, non-delegable responsibility and legal liability for all actions executed by an entity. The operator must audit filesystem permissions, command-line whitelists, external MCP server integrations, and messaging access controls prior to enabling autonomous operation. Under no circumstances should unconstrained shell execution or destructive tools be granted without active human oversight.

## Disclaimer of warranties ("AS IS")

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SOFTWARE, ACCOMPANYING DOCUMENTATION, SPATIAL RUNTIMES, AND ASSOCIATED CODE REPOSITORIES ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS, WITH ALL FAULTS AND DEFECTS, WITHOUT WARRANTY OF ANY KIND.

THE CONTRIBUTORS, MAINTAINERS, AUTHORS, AND COPYRIGHT HOLDERS SPECIFICALLY AND EXPRESSLY DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, QUIET ENJOYMENT, SYSTEM INTEGRATION, ACCURACY, TIMELINESS, COMPLETENESS, FREEDOM FROM PROGRAM BUGS, COMPUTER VIRUSES, OR MALICIOUS CODE, AND NON-INFRINGEMENT OF THIRD-PARTY INTELLECTUAL PROPERTY RIGHTS.

## Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL THE CONTRIBUTORS, MAINTAINERS, AUTHORS, COPYRIGHT HOLDERS, OR AFFILIATES BE LIABLE UNDER ANY LEGAL OR EQUITABLE THEORY—WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, INDEMNITY, OR OTHERWISE—FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, CONSEQUENTIAL, OR RELIANCE DAMAGES WHATSOEVER.

THIS EXCLUSION EXTENDS TO, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, ANTICIPATED SAVINGS, BUSINESS REVENUE, BUSINESS INTERRUPTION, LOSS OR CORRUPTION OF DATA, HARDWARE FAILURE, SYSTEM CORRUPTION, LOSS OF GOODWILL, PRIVACY BREACHES, THIRD-PARTY TOKEN BILLING EXCEEDANCES, FINANCIAL LOSSES INCURRED THROUGH AUTOMATED ACTIONS, OR ANY OTHER COMMERCIAL, PERSONAL, OR BODILY INJURY RESULTING FROM OR RELATED TO YOUR USE, MISUSE, INABILITY TO USE, OR RELIANCE UPON THE SOFTWARE OR ITS GENERATED OUTPUTS.

## Model output and non-deterministic behavior

ngram operates by interfacing with probabilistic machine learning models. Generative outputs are inherently non-deterministic, fallible, and subject to algorithmic hallucinations, confabulations, omissions, contextual distortions, and unexpected behaviors.

**No Professional or Regulated Advice:** Outputs generated by an ngram entity do not constitute licensed medical, psychiatric, psychological, legal, tax, financial, accounting, safety, or engineering advice. Operators, downstream integrators, and end users must never rely on entity output for life-critical, medical, emergency, regulatory, investment, or safety decisions without independent human verification.

## Spatial, hardware, and physical safety

Maintain an unobstructed physical boundary zone and observe hardware manufacturer chaperone guidance when using WebXR surfaces. Obtain meaningful consent before recording, identifying, or analyzing individuals or private environments. Visual frame captures must remain user-controlled.

**Prohibition on High-Risk Deployments:** Under no circumstances may the software, spatial bridge, motion provider, or entity tool subsystem be deployed in connection with high-risk applications, including life support systems, medical devices, nuclear operations, aircraft control, emergency response dispatch, or the actuation of heavy industrial robotics and safety-critical physical machinery.

## Privacy, telemetry, and third-party APIs

Local-first deployment retains transcripts, semantic memory embeddings, and personal data exclusively on operator-controlled hardware. The core ngram runtime contains zero telemetry or centralized surveillance tracking.

When configured in hosted or hybrid modes, prompt context, user messages, and entity memories are dispatched over the network to external third-party API providers (e.g., OpenAI, Anthropic, Google, Venice, OpenRouter, Mistral, xAI). Operators are solely responsible for reviewing and complying with the third-party privacy policies, terms of service, and data retention guidelines of their selected model providers.

Do not put credentials, private Entity state, memory, or relationship history in a shareable shell. A shell contains presentation and behavior.

## Indemnification and defense

You agree to indemnify, defend, and hold harmless project contributors, maintainers, authors, and associates from and against any and all claims, demands, losses, damages, liabilities, judgments, settlements, penalties, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to your deployment, configuration, custom tools, or operation of ngram.

## Prohibited use and regulatory compliance

Operators agree to comply with all applicable local, national, and international laws, export control statutes, and sanctions. The following uses are strictly prohibited:
- Unlawful activities, computer crimes, denial of service, malware generation, or unauthorized network exploitation.
- Deceptive impersonation, identity fraud, non-consensual deepfake generation, or dissemination of intentional disinformation.
- Stalking, harassment, extortion, hate speech, or non-consensual surveillance, recording, or automated profiling.
- Development, enhancement, or operation of conventional, chemical, biological, or nuclear weaponry.
- Bypassing third-party terms of service, security barriers, rate limits, or access controls.

## Vulnerability disclosure

Report vulnerabilities through private security advisories and coordinated disclosure channels. Never publish active exploit scripts, credential leaks, private memory containers, or sensitive user transcripts in public issue trackers.

For the product overview, read [ngram](/index.md). For embodiment-specific behavior, read [ngram Spatial](/spatial/index.md).
