00 Security workbench / browser-accessible layer

NullID ecosystem case study

A browser-first offline security workbench documented through current interface evidence, public source/live reachability at audit time, and explicit browser-sandbox limits.

Evidence
Current receiver-inspection workspace screenshot
Source state
Public source and live site were reachable during the project inventory audit
Boundary
Browser sandbox does not provide device-wide process, socket, persistence, or firewall visibility
NullID receiver inspection workspace showing local package intake and an explicit trust summary
Current browser interface Current NullID receiver-inspection workspace. Local package evidence and trust limits remain visible.
Reading position 01 / Context
01

Context

NullID consolidates security-adjacent local tasks into one browser-accessible workbench: hashing, redaction, sanitization, metadata review, encryption, secure notes, and inspectable package workflows.

The portfolio treats the browser surface as an accessibility layer, not as proof of full device visibility.

02

Constraints

The current public repository records repository validation and release preparation as complete, while live-host verification, restore drill, release-key custody, final tag/deploy, and operator approval remain outside the codebase.

The browser sandbox boundary remains explicit: process, socket, persistence, and firewall visibility require a different authorized local layer.

03

System

The current evidence capture shows receiver inspection: local package intake, visible trust summary, and source-bounded review rather than a decorative screenshot.

NullID Terminal is documented as the authorized local companion, but it remains without a committed safe product screenshot in this portfolio.

04

Decisions

Trust information stays close to the package workflow. The interface names limits instead of implying an external audit or a stable GA contract.

Sensitive operations remain local and explicit; the case study avoids invented metrics, testimonials, or release claims.

05

Failure modes

The main failure risk for presentation is false confidence: a browser workbench can look complete while still lacking OS-wide observation.

The portfolio counters that by pairing NullID with a clearly bounded Terminal layer and by marking missing terminal evidence as pending.

06

Validation

Repository inventory records Node tests, Playwright e2e, visual regression, i18n checks, build/release verification scripts, release readiness docs, and security model documentation in the NullID source.

This case study cites those gates as repository-supported validation categories, not as an external security audit.

07

Outcome

NullID becomes the portfolio proof of security-aware product design: visible state, local workflows, documented boundaries, and honest release status.

The outcome is intentionally framed as 0.1.0 with operational release sign-off pending, not as a finished 1.0 security product.

TM Interactive artifact

Threat-model explorer

Select a boundary to inspect the threat, defensive decision, and evidence source recorded by the portfolio.

ThreatSensitive data can enter the workflow with unknown provenance.

DecisionKeep intake local and make the trust summary visible before the user proceeds.

EvidenceCurrent receiver-inspection workspace screenshot.