00 Security workbench / browser-accessible layer
NullID ecosystem case study
A browser-first offline security workbench documented through current interface evidence, public source/live reachability at audit time, and explicit browser-sandbox limits.
- Evidence
- Current receiver-inspection workspace screenshot
- Source state
- Public source and live site were reachable during the project inventory audit
- Boundary
- Browser sandbox does not provide device-wide process, socket, persistence, or firewall visibility
Context
NullID consolidates security-adjacent local tasks into one browser-accessible workbench: hashing, redaction, sanitization, metadata review, encryption, secure notes, and inspectable package workflows.
The portfolio treats the browser surface as an accessibility layer, not as proof of full device visibility.
Constraints
The current public repository records repository validation and release preparation as complete, while live-host verification, restore drill, release-key custody, final tag/deploy, and operator approval remain outside the codebase.
The browser sandbox boundary remains explicit: process, socket, persistence, and firewall visibility require a different authorized local layer.
System
The current evidence capture shows receiver inspection: local package intake, visible trust summary, and source-bounded review rather than a decorative screenshot.
NullID Terminal is documented as the authorized local companion, but it remains without a committed safe product screenshot in this portfolio.
Decisions
Trust information stays close to the package workflow. The interface names limits instead of implying an external audit or a stable GA contract.
Sensitive operations remain local and explicit; the case study avoids invented metrics, testimonials, or release claims.
Failure modes
The main failure risk for presentation is false confidence: a browser workbench can look complete while still lacking OS-wide observation.
The portfolio counters that by pairing NullID with a clearly bounded Terminal layer and by marking missing terminal evidence as pending.
Validation
Repository inventory records Node tests, Playwright e2e, visual regression, i18n checks, build/release verification scripts, release readiness docs, and security model documentation in the NullID source.
This case study cites those gates as repository-supported validation categories, not as an external security audit.
Outcome
NullID becomes the portfolio proof of security-aware product design: visible state, local workflows, documented boundaries, and honest release status.
The outcome is intentionally framed as 0.1.0 with operational release sign-off pending, not as a finished 1.0 security product.
TM Interactive artifact
Threat-model explorer
Select a boundary to inspect the threat, defensive decision, and evidence source recorded by the portfolio.
ThreatSensitive data can enter the workflow with unknown provenance.
DecisionKeep intake local and make the trust summary visible before the user proceeds.
EvidenceCurrent receiver-inspection workspace screenshot.