Platforms and enforcement modes
A platform record describes how an integration could apply a rule. In the public sandbox, platform names, capabilities, and statuses are synthetic fixtures used to test discovery, UI, and mode-aware logic.
| Mode | Intended meaning |
|---|---|
dns | A network integration could translate supported categories into resolver policy |
device | A device agent could apply supported controls locally |
api_write | A platform adapter could write settings through an authorized API |
manual_attested | A guardian completes guided steps and records the outcome |
coming_soon | Capability is not available |
Do not render a sandbox completed or partial state as proof that a named company accepted a
rule. The current registry does not demonstrate live NextDNS, CleanBrowsing, Control D, Apple,
Android, console, streaming, or social-platform adapters.
The target architecture keeps decisions local where possible and uses signed receipts to make outcomes auditable. A production adapter and receipt must be validated independently before they can support compliance evidence.
See Implementation status and join the design-partner beta to help define a bounded real-world adapter pilot.