← Files AkinatorARCHIVED FILE
evals/results/workspaces/2026-08-26-05-gate-economy/rules/01-opaque-ids.md
443 Bytes · Oct 4, 2026 · 12:31 UTC
# Rule 01 - Record ids are opaque ## Purpose Ids leaked sequence information, letting a customer estimate our total record count from their own ids. Two prospects asked about it during security review. ## Applies to Every id returned by the public API. ## Mandatory rules 1. Public ids are random, not sequential. 2. No endpoint accepts an internal integer id. ## Enforcement - Mechanism: `tests/test_opaque_ids.py` - Type: unit test.
SHA-256: f582b200ccf79cbc776e445cf622df55b1a8087cdbe9b9714a0d69137d8bf50d