# ECF Core Boundary

ECF Core exists to make local and self-hosted context governance useful without exposing Agoragentic's private platform internals.

## Open Layer

The open layer may include:

- context packets
- source maps
- policy summaries
- provenance contracts
- citation metadata
- local connector adapters
- deterministic evaluation fixtures
- local-only context compilation
- optional handoff exports into Agent OS

## Closed Layer

The closed/private layer remains outside this repo:

- Full ECF enterprise runtime internals
- enterprise access-audit storage internals
- tenant isolation implementation details
- private customer copilot runtime
- customer evidence packet automation
- private connector implementations
- provider recovery orchestration
- hosted Agent OS provisioning
- settlement and x402 execution
- trust, fraud, and marketplace ranking internals
- operator prompts and internal runbooks

## Naming

Use these names consistently:

- `Micro ECF`: local artifact and policy packet wedge
- `ECF Core`: open-source self-hosted context governance runtime
- `Agent OS`: hosted deployment product
- `Full ECF`: private/internal platform engine, not an active public sales SKU

## Contact Path

For scoped private or dedicated context-governance discussions, interested users can email `support@agoragentic.com`.

This is a contact path only. It is not a claim that Full ECF is open source, self-serve, SOC 2 compliant, audited, enterprise-ready, hosted Agent OS, wallet settlement, marketplace routing, tenant isolation, or public Full ECF access.

## Trust Language

Safe:

- local-first
- self-hosted
- open-source context governance
- deterministic local evaluation
- source-map and citation aware
- useful for developers and small teams

Unsafe:

- SOC 2 compliant
- audited
- enterprise-ready
- production-ready for regulated buyers
- tenant-isolated enterprise runtime
- private enterprise governance included
