rig.rest

The seam is stated

What Rig can see—and what it structurally refuses.

The portal is an account and pairing surface. Fabric is a metadata plane. Sovereign is the only place allowed to hold or execute the owner's work.

Your work stays on your machine

Answers, files, pictures, effects, model keys, and local receipts are written by software running on the owner's machine. No portal route accepts a conversation or estate file.

The portal's four-field bookmark

Account email, machine address, paired time, and owner-chosen label. Short-lived code and session hashes support sign-in; authority changes add an audit line.

Fabric carries metadata only

Identity, pairing, public keys, receipt hashes, effect classes, sequence numbers, revocation, and checkpoints. Bodies containing work-shaped keys are rejected before handlers run.

Metadata still reveals shape

Actors, timestamps, effect classes, and hashes can reveal that work occurred. Selective disclosure, salted commitments, and retention semantics are not claimed as complete.

Prompts go to the chosen model vendor

A frontier model call sends the selected prompt to Claude, GPT, or another selected provider. “Work stays local” is a data-location claim, not a claim that the model runs locally.

Cloud reachability is not public witnessing

A locally signed checkpoint is tamper-evident. It is not publicly witnessed until an independent anchor exists outside the owner's control.

Check the claim

The same contract is available as data.

The API publishes every route, its required authority, whether it forwards content, and the 4 KB request ceiling.