# 06 — Publishing rules and boundaries

This site has the strictest publishing rules in the network, because it publishes **other companies' words** and handles **individuals' financial lives**. The rules are the product's legal armour; treat them as build requirements.

## 1. The register's constitution — enforced, not remembered

1. **Record, never verdict. No adjectives anywhere** — in entries, headlines, URLs, or metadata. A CI check should grep register pages for a published adjective blocklist; cheap, and it makes the rule structural.
2. **Verbatim replies, requester details removed.** The redaction is a pipeline step, not an editorial pass.
3. **Silence is a row, not a blank.** "No reply as at [date]" is a fact.
4. **"We do not hold that" is recorded neutrally.** The inconsistency test is run only against the company's own published claims, quoted and linked.
5. **Never publish a first refusal.** Two asks, published interval.
6. **A published policy page counts as an answer** and is recorded as such.
7. **A solicitor reviews the publishing rule and the first entry before it goes live.** The source flags this explicitly; it is the one external dependency in the launch list.

## 2. Personal data — the hard lines

- **The unit of the register is a company's behaviour, never a person's case.** No register entry is traceable to a requester.
- **Claim files live in the client's own vault.** The operator holds *"only what a live claim requires"*. Nothing personal in browser storage; nothing personal in the repo; nothing personal in the register vault.
- **Real-world examples are published with no personal data** — the source's instruction verbatim.
- **SARs are never leverage** — merit before request, decline rate published, authority evidenced.

## 3. Licensing

Site content **CC BY 4.0**, stamped and gated as across the network. The register data: CC BY, in its own vault (the re-pointable asset). Company replies quoted in entries are **quotation for reporting** — verbatim, attributed, dated; that is the substantial-truth posture and also fair-dealing hygiene. The two source briefs ship in `sources/` under their own CC BY notices.

## 4. Do not publish

- **Any client's personal or financial data** — including the founder's own statements (the March pipeline ran on them; the *workflow* is publishable, the statements never).
- **Any characterisation of a named company** — the constitution, restated as a redaction rule.
- **The card-issuer lever as an offered service** — perimeter advice first.
- **Legal pages without their as-at date and status** — an undated legal page is treated as a leak, not a draft.
- **Unreviewed first entries** — rule 7 above.
- From the wider estate: the standard exclusions (alchemist tree, named-individual GRC records) apply to any corpus material quoted.

## 5. The tensions, published

Per house pattern, the site publishes its own tensions — the source supplies them: the refund-as-pretext (customers want the thing that is not the product) · record-only will feel toothless to some readers · neutral data-minimisation treatment removes the easy headline · the inconsistency test is slow because it requires reading marketing carefully · the good-path-cheap rule lets a company answer with one page and no change · founder-led selection until the rule is published · **and the closing window: the best year is the least defensible pitch.**

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
