CITADEL / Data boundaries
Foundation Vault
Scoped synthetic queries with a visible cross-tenant refusal.
Interactive hereFICTIONAL RECORDSBrowser-only example. Nothing is sent or stored on a server.
Teaching model, not server security. Both fictional tenants exist in the browser bundle. A real application must enforce this boundary on its server.
Access refused
Requested scope does not match the active session.
0 RECORDS RETURNED
No record content returned.
Refusal contract
Unknown sessions fail closed. A cross-scope request returns an empty array with no foreign record content. An unknown record and a record outside scope receive the same unavailable response. This browser example is inspectable; it does not promise confidentiality or authenticate visitors.