← Home

Ethical Framework v0.1 Skeleton

HIFP · v3 reference · rendered from HIFP-ethical-framework-v0.1-skeleton.md
Reference · v3 vintage

HIFP — Ethical Framework v0.1 (Skeleton)

Purpose. Through-line document that sits above [[HIFP-advice-boundary-spec-v0.1]] (what we say), [[HIFP-model-fairness-protocol-v0.1]] (how we model), [[HIFP-data-lifecycle-sla-v0.1]] (how we hold data), and [[HIFP-life-insurance-judo-memo-v0.1]] (what we won't build). Names the why behind all four so any downstream decision can be checked against a single set of commitments. Date. 2026-09-04 (v0.1 skeleton · weekend homework pre-Monday 2026-09-07 alignment) Author. Brandon (skeleton). Sindhu-review required before v0.1 lands. Status. Skeleton for Monday reaction — one-page frame + section stubs. Full v0.1 expansion post-alignment. Companion. [[HIFP-session-notes-2026-09-04-demo]] §4.1 (Sindhu-requested); [[HIFP-open-items-ledger-v0.1]] §3.17.


Governing Commitment

HIFP exists to help users ask better questions of themselves and their trusted advisors — never to replace those advisors, never to build files that others can turn against the user, never to trade user primacy for scale. Three consequences follow — each expressed as a commitment, each with an internal governance mechanic, each with a named refusal.


§1 · Commitment 1 — User Primacy

We work for the user. Full stop.

Not for the carrier. Not for the advisor. Not for the employer sponsoring the seat. Not for the chain partner integrating our surface. Not for the LLM provider whose model powers the assistant. When any of those parties' interests conflict with the user's, the user wins by default, and the conflict is disclosed to the user.

Governance mechanic

Refusal

We will not accept partnership economics that require us to shade outputs, prioritize partner-branded solutions, or gate user data behind partner walls. This forecloses some obvious revenue paths. That is the point.

Rooted in

[[HIFP-advice-boundary-spec-v0.1]] · [[HIFP-life-insurance-judo-memo-v0.1]] §3.5 (rejected option) · Fatima 2026-09-04 quote: "We are not advisers. We do not give financial or fiduciary advice."


§2 · Commitment 2 — Boundary Integrity

We ask questions. We do not give answers.

Planning is what a user does with an advisor and with the plan HIFP helps them build. HIFP surfaces the numbers, models the tradeoffs, explains the charts, prompts the conversations. HIFP does not tell the user what to do with their money, their body, or their care. When a user asks "what should I do?" HIFP responds with "here is what your plan says, here is what to ask your advisor" — never with a directive.

Governance mechanic

Refusal

We will not ship a feature that gives users a directive answer to a fiduciary question — even when they explicitly ask for one, even when the model is confident, even when a competitor does. The answer to "what should I do?" is architecturally different from the answer to "what does my plan say?"

Rooted in

[[HIFP-advice-boundary-spec-v0.1]] · [[HIFP-red-team-v3]] T1 (regulatory precedent risk) + T8 (Gate 7) · Sindhu 2026-09-04 quote: "The framing of this as a question-asking tool as opposed to an answering tool is so critical."


§3 · Commitment 3 — Transparency with Agency

Users see everything. Users control everything. Users can leave with everything they gave us.

Every data source connected is visible. Every AI response is auditable. Every share event is logged, and can be revoked. Every consent is per-event and per-purpose, never bundled. Every user can export their data (in planning-outputs form — see [[HIFP-life-insurance-judo-memo-v0.1]] §3.1) and every user can delete their record entirely, with cryptographic evidence of deletion.

Governance mechanic

Refusal

We will not add a "dark-pattern" data flow, bundle consents, or make deletion harder than signup. If it takes a click to opt in, it takes a click to opt out.

Rooted in

[[HIFP-data-lifecycle-sla-v0.1]] · [[HIFP-security-architecture-v0.1]] · [[HIFP-life-insurance-judo-memo-v0.1]] §3.1 · Brandon 2026-09-04 quote: "there's an export, there's a delete. Like I think we have to be like really super strong on that."


§4 · Cross-cutting principles

4.1 Model fairness — condition-spectrum, not condition-binary

Planning inputs and health-model outputs treat conditions as spectra (severity, trajectory, projected cost by state), not binary flags. Sindhu's diabetes-as-monolith critique (2026-09-04) is the exemplar — the framework applies to every condition modeled. See [[HIFP-model-fairness-protocol-v0.1]] v0.2 update.

4.2 Bias audit — quarterly + published

Model-fairness protocol runs quarterly bias audits across demographic axes; results are published in the annual transparency report. Findings feed back into model retraining.

4.3 Escalation to human — never optional

Any Cat-4 (clinical-escalation) or equivalent-severity planning event escalates to a human (partner physician, credentialed advisor, or HIFP-side clinical lead) — regardless of model confidence, regardless of business-continuity cost.

4.4 Third-party risk

Every integration partner, every LLM provider, every subprocessor is evaluated against this framework at onboarding and annually. A partner that cannot commit to these principles cannot integrate.


§5 · Governance body


§6 · Review cadence


§7 · What v0.1 (full) needs to add post-Monday


End of skeleton. Monday reaction question for Sindhu + Fatima: do the three commitments capture the ethical center of gravity, or is there a fourth commitment (candidate: "Category discipline" — refusal to expand into adjacent lanes that would collapse the boundary) that belongs alongside them? Full v0.1 lands within 14 days post-Monday alignment.