06 — Publishing rules and boundaries
This site has the strictest publishing rules in the network, because it publishes other companies' words and handles individuals' financial lives. The rules are the product's legal armour; treat them as build requirements.
1. The register's constitution — enforced, not remembered
- Record, never verdict. No adjectives anywhere — in entries, headlines, URLs, or metadata. A CI check should grep register pages for a published adjective blocklist; cheap, and it makes the rule structural.
- Verbatim replies, requester details removed. The redaction is a pipeline step, not an editorial pass.
- Silence is a row, not a blank. "No reply as at [date]" is a fact.
- "We do not hold that" is recorded neutrally. The inconsistency test is run only against the company's own published claims, quoted and linked.
- Never publish a first refusal. Two asks, published interval.
- A published policy page counts as an answer and is recorded as such.
- A solicitor reviews the publishing rule and the first entry before it goes live. The source flags this explicitly; it is the one external dependency in the launch list.
2. Personal data — the hard lines
- The unit of the register is a company's behaviour, never a person's case. No register entry is traceable to a requester.
- Claim files live in the client's own vault. The operator holds "only what a live claim requires". Nothing personal in browser storage; nothing personal in the repo; nothing personal in the register vault.
- Real-world examples are published with no personal data — the source's instruction verbatim.
- SARs are never leverage — merit before request, decline rate published, authority evidenced.
3. Licensing
Site content CC BY 4.0, stamped and gated as across the network. The register data: CC BY, in its own vault (the re-pointable asset). Company replies quoted in entries are quotation for reporting — verbatim, attributed, dated; that is the substantial-truth posture and also fair-dealing hygiene. The two source briefs ship in sources/ under their own CC BY notices.
4. Do not publish
- Any client's personal or financial data — including the founder's own statements (the March pipeline ran on them; the workflow is publishable, the statements never).
- Any characterisation of a named company — the constitution, restated as a redaction rule.
- The card-issuer lever as an offered service — perimeter advice first.
- Legal pages without their as-at date and status — an undated legal page is treated as a leak, not a draft.
- Unreviewed first entries — rule 7 above.
- From the wider estate: the standard exclusions (alchemist tree, named-individual GRC records) apply to any corpus material quoted.
5. The tensions, published
Per house pattern, the site publishes its own tensions — the source supplies them: the refund-as-pretext (customers want the thing that is not the product) · record-only will feel toothless to some readers · neutral data-minimisation treatment removes the easy headline · the inconsistency test is slow because it requires reading marketing carefully · the good-path-cheap rule lets a company answer with one page and no change · founder-led selection until the rule is published · and the closing window: the best year is the least defensible pitch.
This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
== briefs/v0.33.62__subscriptions-brief-pack__07__gaps-and-open-questions.md