# HIFP — Ethical Framework v0.1 (Skeleton)

**Purpose.** Through-line document that sits **above** [[HIFP-advice-boundary-spec-v0.1]] (what we say), [[HIFP-model-fairness-protocol-v0.1]] (how we model), [[HIFP-data-lifecycle-sla-v0.1]] (how we hold data), and [[HIFP-life-insurance-judo-memo-v0.1]] (what we won't build). Names the *why* behind all four so any downstream decision can be checked against a single set of commitments.
**Date.** 2026-09-04 (v0.1 skeleton · weekend homework pre-Monday 2026-09-07 alignment)
**Author.** Brandon (skeleton). Sindhu-review required before v0.1 lands.
**Status.** Skeleton for Monday reaction — one-page frame + section stubs. Full v0.1 expansion post-alignment.
**Companion.** [[HIFP-session-notes-2026-09-04-demo]] §4.1 (Sindhu-requested); [[HIFP-open-items-ledger-v0.1]] §3.17.

---

## Governing Commitment

**HIFP exists to help users ask better questions of themselves and their trusted advisors — never to replace those advisors, never to build files that others can turn against the user, never to trade user primacy for scale.** Three consequences follow — each expressed as a commitment, each with an internal governance mechanic, each with a named refusal.

---

## §1 · Commitment 1 — User Primacy

**We work for the user. Full stop.**

Not for the carrier. Not for the advisor. Not for the employer sponsoring the seat. Not for the chain partner integrating our surface. Not for the LLM provider whose model powers the assistant. When any of those parties' interests conflict with the user's, the user wins by default, and the conflict is disclosed to the user.

### Governance mechanic
- Every partnership deal reviewed against a user-primacy check: does this arrangement create any incentive to shape planning outputs in a direction the user would not choose absent the arrangement? If yes, deal is off — or the arrangement is restructured until the answer is no.
- Every AI response reviewed against a "who is this actually helping right now" filter as part of the Advice-Boundary Classifier.
- Sindhu (CCO, per §7.2 recommendation) owns user-primacy adjudication when disputed.

### Refusal
**We will not accept partnership economics that require us to shade outputs, prioritize partner-branded solutions, or gate user data behind partner walls.** This forecloses some obvious revenue paths. That is the point.

### Rooted in
[[HIFP-advice-boundary-spec-v0.1]] · [[HIFP-life-insurance-judo-memo-v0.1]] §3.5 (rejected option) · Fatima 2026-09-04 quote: *"We are not advisers. We do not give financial or fiduciary advice."*

---

## §2 · Commitment 2 — Boundary Integrity

**We ask questions. We do not give answers.**

Planning is what a user does *with* an advisor and *with* the plan HIFP helps them build. HIFP surfaces the numbers, models the tradeoffs, explains the charts, prompts the conversations. HIFP does not tell the user what to do with their money, their body, or their care. When a user asks "what should I do?" HIFP responds with "here is what your plan says, here is what to ask your advisor" — never with a directive.

### Governance mechanic
- Advice-Boundary Classifier + adversarial test set (500+ prompts at MVP, 5K target per Red Team T15) enforces per-response.
- Every classifier failure logged, root-caused, and fed back into the corpus.
- Full user-facing audit log — every AI response is inspectable by the user after the fact, showing what was asked, what was returned, and what boundary check was applied.
- Quarterly independent red-team pass on the classifier corpus.

### Refusal
**We will not ship a feature that gives users a directive answer to a fiduciary question — even when they explicitly ask for one, even when the model is confident, even when a competitor does.** The answer to "what should I do?" is architecturally different from the answer to "what does my plan say?"

### Rooted in
[[HIFP-advice-boundary-spec-v0.1]] · [[HIFP-red-team-v3]] T1 (regulatory precedent risk) + T8 (Gate 7) · Sindhu 2026-09-04 quote: *"The framing of this as a question-asking tool as opposed to an answering tool is so critical."*

---

## §3 · Commitment 3 — Transparency with Agency

**Users see everything. Users control everything. Users can leave with everything they gave us.**

Every data source connected is visible. Every AI response is auditable. Every share event is logged, and can be revoked. Every consent is per-event and per-purpose, never bundled. Every user can export their data (in planning-outputs form — see [[HIFP-life-insurance-judo-memo-v0.1]] §3.1) and every user can delete their record entirely, with cryptographic evidence of deletion.

### Governance mechanic
- Data-Lifecycle SLA specifies collection, retention, access, and deletion per data class.
- User-facing consent UX audited annually against dark-pattern criteria.
- Deletion is *actual deletion* — not soft-delete, not "we still have your data but promise not to use it." Verified cryptographically and reflected in audit log.
- Data-scope architecture (from Judo Memo §3.1) — HIFP does not produce raw-data exports that could be weaponized against the user.

### Refusal
**We will not add a "dark-pattern" data flow, bundle consents, or make deletion harder than signup.** If it takes a click to opt in, it takes a click to opt out.

### Rooted in
[[HIFP-data-lifecycle-sla-v0.1]] · [[HIFP-security-architecture-v0.1]] · [[HIFP-life-insurance-judo-memo-v0.1]] §3.1 · Brandon 2026-09-04 quote: *"there's an export, there's a delete. Like I think we have to be like really super strong on that."*

---

## §4 · Cross-cutting principles

### 4.1 Model fairness — condition-spectrum, not condition-binary
Planning inputs and health-model outputs treat conditions as spectra (severity, trajectory, projected cost by state), not binary flags. Sindhu's diabetes-as-monolith critique (2026-09-04) is the exemplar — the framework applies to every condition modeled. See [[HIFP-model-fairness-protocol-v0.1]] v0.2 update.

### 4.2 Bias audit — quarterly + published
Model-fairness protocol runs quarterly bias audits across demographic axes; results are published in the annual transparency report. Findings feed back into model retraining.

### 4.3 Escalation to human — never optional
Any Cat-4 (clinical-escalation) or equivalent-severity planning event escalates to a human (partner physician, credentialed advisor, or HIFP-side clinical lead) — regardless of model confidence, regardless of business-continuity cost.

### 4.4 Third-party risk
Every integration partner, every LLM provider, every subprocessor is evaluated against this framework at onboarding and annually. A partner that cannot commit to these principles cannot integrate.

---

## §5 · Governance body

- **Ethical Framework Steward.** Sindhu (CCO, per §7.2 recommendation). Final adjudicator on user-primacy disputes; owns quarterly review cadence.
- **Model + Bias Review Board.** Sindhu (chair) + external biostatistician (Ledger §5.5) + Medical Lead advisor (§5.3). Meets quarterly, reviews classifier findings + fairness-audit results.
- **Boundary Review Board.** Brandon + counsel + Advice-Boundary lead engineer. Meets on every material product-scope decision.
- **User-Facing Escalation.** Any user can escalate a decision to human review through the app; response SLA 5 business days.

---

## §6 · Review cadence

- **Framework text.** Reviewed annually or on material product-scope change; version bumps published with change log.
- **Metrics** (classifier failure rate, bias-audit findings, user-escalation volume + resolution). Published in annual transparency report.
- **External audit.** Independent ethics-and-compliance audit annually starting Y2.

---

## §7 · What v0.1 (full) needs to add post-Monday

- Full text of the three commitments (each 1–2 pages, not paragraph-length).
- Governance mechanic detail (roles, cadences, escalation paths, sanction if violated).
- Refusal list expansion (currently 3; likely 6–8 in full form).
- Rooted-in reference matrix — every downstream artifact traceable to a governing commitment.
- Public-facing extract — plain-language version that can live on the marketing site as HIFP's ethical charter.
- Advisor + partner + investor readouts — how the framework is communicated to each audience, and what it commits us to relative to each.

---

*End of skeleton. Monday reaction question for Sindhu + Fatima: do the three commitments capture the ethical center of gravity, or is there a fourth commitment (candidate: "Category discipline" — refusal to expand into adjacent lanes that would collapse the boundary) that belongs alongside them? Full v0.1 lands within 14 days post-Monday alignment.*
