UUtilbelt GME working title

The claim, and how to check it

This page is written for the person at the institution who has to approve the tool. It is short on purpose. Every statement comes with a way to verify it that does not require trusting us.

1. The tool runs on the program's computer and holds nothing anywhere else

There is no hosted service, no account, no upload. We are not a data processor because no data is ever processed by us. There is nothing on our side to review.

Check: there is no sign-in, no URL to visit and no vendor portal. The release is a download and a checksum.

2. It opens no network connection

No telemetry, no licence check, no update ping, no fonts or scripts fetched from anywhere. Updates are manual downloads.

Check: the dashboard file carries a content-security policy that forbids every connection (default-src 'none'; connect-src 'none'). Open it with the network disconnected; it works the same. Our build refuses to write a dashboard that references a URL. For the generator itself, the packaging chosen in discovery comes with the same test written down.

3. Nothing needs installing, and no administrator rights are needed

The packaging is decided by testing on a locked-down hospital PC with a coordinator, not by preference. Whichever form wins, it runs from a folder the program chooses.

Check: the release notes name the form (a single file, or an executable with its signing details) and the exact test it passed. Until discovery ends, this is the one statement on this page that is a plan rather than a fact.

4. Files that name residents say so, everywhere

The CCC dashboard contains identifiable resident data by design. Its file name and every screen say so. It is never the input to an AI step. Output folders are named as safe to share or not safe to share, and resident-level output is never designed to leave the program.

Check: the build refuses to write a CCC file whose name lacks NOT-SAFE-TO-SHARE. The banner cannot be turned off by configuration.

5. Small groups are never shown as numbers

Any program-level figure built from fewer people than the program's threshold (default five) is shown as suppressed. The threshold is set per program, not per chart.

Check: the verification tab lists any value whose count is below the threshold but is not suppressed as a mismatch, and the dashboard stays unverified until it is fixed.

6. No model touches a number

Every value is produced by deterministic code and carries a pointer to its cell, row or page. Where a program chooses to use AI, it is their own institution-approved account, working only on an aggregate, suppressed, de-identified brief that has passed an automated de-identification pass and an independent second check.

Check: the verification tab reconciles every displayed value to its source and shows the count matched. A named reviewer's sign-off is bound to the exact bytes of the analytics; a rebuild removes it.

What each release ships

  1. A checksum for every file.
  2. This page as a plain-language security note, versioned with the release.
  3. A synthetic demo package, so the tool can be exercised end to end with no program data at all.
  4. The source of the dashboard file is readable: it is one HTML file with the modules inline. Nothing is minified or obfuscated.

What we do not ask for

A firewall exception. A software install. An account. A data-use agreement with us. Access to anything.

This page describes engineering controls. It is not legal advice, and it does not replace the institution's own FERPA, records-retention and AI-use policies. Where the file may live and who may open it is the program's decision under those policies.