Pusat Pengetahuan (Wiki)
Panduan teknikal dan rujukan rasmi untuk menggunakan ekosistem Orbika Lucid dan CoLucid CLI (ask).
1. Pemasangan Asas (Linux)
Orbika Lucid diedarkan sebagai fail mudah alih .AppImage untuk sistem operasi Linux. Ia membenarkan pemasangan tanpa masalah kebergantungan (dependencies).
# Berikan kebenaran execute
chmod +x OrbikaLucid-x86_64.AppImage
# Jalankan aplikasi
./OrbikaLucid-x86_64.AppImage
2. Menggunakan CoLucid CLI (ask)
Selepas pemasangan, anda boleh memanggil arahan ask terus dari terminal tanpa melancarkan GUI.
Soalan Terus (Direct Prompt)
ask "bagaimana untuk menyemak senarai port aktif di Ubuntu?"
Diagnosis Ralat (Piping)
Salurkan log ralat untuk diagnosis pantas:
cat /var/log/syslog | tail -n 50 | ask "kenapa perkhidmatan docker gagal bermula?"
3. Pengurusan Keselamatan (MitM Gate)
Sistem MitM secara automatik menyekat arahan luar biasa. Untuk mendaftar arahan ke dalam senarai putih (whitelist), edit fail konfigurasi settings.json:
{
"security": {
"whitelist": ["systemctl restart nginx", "ufw status"]
}
}
4. Audit Vault
Setiap kelulusan arahan yang diberikan oleh pengguna [y/N] direkodkan dengan tandatangan HMAC. Log ini boleh ditemui di storage/audit_vault.json untuk tujuan pengauditan IT korporat.
5. Pengesahan Zero-Trust & Polisi Pelesenan
Orbika Lucid dibina atas prinsip kedaulatan data yang ketat. Walau bagaimanapun, untuk menyokong ciri lanjutan seperti carian internet, integrasi MCP, dan pelesenan komersial, garis panduan berikut digunakan untuk membuktikan dan mengawal keselamatan sistem anda:
A. Ujian Keasingan Rangkaian (Network Isolation)
Semua panggilan inferens LLM dikendalikan 100% secara tempatan. Anda boleh mengesahkan ini dengan memutuskan sambungan internet peranti anda atau memantau aktiviti rangkaian (contohnya menggunakan Wireshark) semasa bersembang. Anda akan melihat bahawa perisian ini hanya berkomunikasi dengan port tempatan (localhost 127.0.0.1:11434).
B. Kebenaran Carian Internet (Brave/DDG) & MCP
Apabila anda mengaktifkan keupayaan carian atas talian (Brave Search atau DuckDuckGo) atau menyambung ke pelayan MCP (Model Context Protocol) luaran:
- Kelulusan Manual Lalai: Setiap arahan atau capaian fail yang dicadangkan oleh alat MCP atau carian akan dipintas oleh MitM Gate untuk kelulusan manual anda
[y/N]. Tiada tindakan dijalankan secara senyap.
- Autonomi Pilihan Pengguna: Untuk mengekalkan kelancaran aliran kerja anda, anda boleh menetapkan kebenaran autonomi (auto-approval) khusus untuk setiap MCP tool atau arahan tertentu di dalam tetapan anda tanpa perlu menyekatnya dalam sandbox yang merumitkan.
- Capaian Tanpa Orang Tengah: Pertanyaan carian dihantar secara terus dari komputer anda ke penyedia carian menggunakan kunci API peribadi anda yang disimpan secara lokal. Tiada data carian yang dialirkan atau disimpan di pelayan Orbika.
C. Polisi Telemetri Pelesenan (Licensing Telemetry)
Untuk menyokong model langganan komersial, perisian ini memerlukan satu semakan sambungan telemetri yang sangat minimum:
- Pemisahan Data Mutlak: Telemetri pelesenan diasingkan sepenuhnya daripada data perbualan anda. Kandungan sembang, kod sumber, dan sejarah terminal anda tidak akan dihantar.
- Payload Minimum & Lut Sinar: Sambungan hanya menghantar data pengesahan asas (kunci lesen yang telah di-hash + hash perkakasan mesin anda) sekali dalam sebulan untuk menyemak status langganan.
- Sokongan Mod Luar Talian (30-Hari): Sekiranya peranti anda tiada sambungan internet, aplikasi tetap boleh dijalankan tanpa sebarang gangguan sehingga 30 hari sebelum pengesahan lesen seterusnya diperlukan.
D. Perlindungan Dokumen Sensitif (Penyelidik, Wartawan & Pelajar)
Bagi pengguna bukan pengaturcara yang menggunakan Orbika Lucid untuk membaca ratusan fail PDF, menganalisis dokumen penyelidikan, atau membina peta kognitif visual:
- Tiada Kebocoran Harta Intelek: Semua teks dokumen, fail PDF yang dimuat naik, data RAG (Retrieval-Augmented Generation), dan arkib peta kognitif diproses sepenuhnya di dalam mesin anda. Tiada fail atau petikan teks yang dihantar ke awan.
- Sahkan Secara Fizikal: Anda boleh menyemak direktori konfigurasi tempatan di
~/.config/Orbika/Orbika Lucid/ (atau folder setara pada sistem anda). Anda akan mendapati semua pangkalan data vektor (vector database) dan fail cache dokumen disimpan secara setempat di situ.
- Sekatan Penuaian Data: Oleh kerana tiada sambungan awan pihak ketiga, tiada mana-mana organisasi yang boleh menggunakan jurnal kajian anda, nota berita wartawan yang sensitif, atau maklumat tesis pelajar untuk melatih model kecerdasan buatan mereka.
E. Polisi Laporan Ralat Selamat (Secure Crash Reporting)
Untuk membantu kami mendiagnosis pepijat sistem dengan pantas tanpa mendedahkan data peribadi anda, kami menggunakan protokol laporan ralat selamat:
- Penyulitan RSA Tempatan (Offline RSA Encryption): Log ralat (traceback) dan alamat e-mel berdaftar disulitkan secara kriptografi menggunakan Kunci Awam (Public Key) terus di komputer anda sebelum ia dihantar melintasi rangkaian.
- Persetujuan Telus & Manual: Laporan ralat tidak akan dihantar secara senyap. Apabila aplikasi terhenti secara luar biasa, kotak dialog akan dipaparkan untuk menunjukkan butiran log ralat mentah dan meminta kelulusan anda secara nyata sebelum menghantar.
- Penyimpanan Pelayan yang Selamat: Laporan ralat disimpankan di dalam pelayan web kami dalam keadaan terenkripsi sepenuhnya, dan hanya boleh dinyahsulit secara offline oleh pentadbir sistem menggunakan Kunci Peribadi (Private Key) yang disimpan secara fizikal jauh dari server.
Knowledge Base (Wiki)
Official technical documentation and references for the Orbika Lucid ecosystem and CoLucid CLI (ask).
1. Basic Installation (Linux)
Orbika Lucid is distributed as a portable .AppImage package for Linux operating systems, enabling dependency-free execution.
# Grant execution permissions
chmod +x OrbikaLucid-x86_64.AppImage
# Launch the application
./OrbikaLucid-x86_64.AppImage
2. Using CoLucid CLI (ask)
Once installed, you can call the ask command directly from your terminal standard prompt without starting the GUI.
Direct Prompt
ask "how to check the list of active ports on Ubuntu?"
Error Diagnosis (Piping)
Pipe error logs directly for instantaneous diagnosis:
cat /var/log/syslog | tail -n 50 | ask "why did the docker service fail to start?"
3. Security Management (MitM Gate)
The MitM Gate automatically intercept unusual commands. To register commands in the whitelist, edit the local settings.json file:
{
"security": {
"whitelist": ["systemctl restart nginx", "ufw status"]
}
}
4. Audit Vault
Every single command approval granted by the user [y/N] is recorded with a HMAC signature. This immutable log is saved in storage/audit_vault.json for enterprise IT audits.
5. Zero-Trust Verification & Licensing Policy
Orbika Lucid operates on a strict data sovereignty model. To support advanced integrations such as web search, Model Context Protocol (MCP) servers, and commercial subscriptions, the following guidelines define how we guarantee zero-trust security:
A. Network Isolation Audit
All LLM inference calls are handled locally. You can easily verify this by disconnecting your device from the internet or using packet analyzers (such as Wireshark) during a chat session. The application communicates strictly via local host ports (localhost 127.0.0.1:11434).
B. Web Searches (Brave/DDG) & MCP Server Trust Model
When enabling internet search engines (Brave Search / DuckDuckGo) or integrating external Model Context Protocol (MCP) servers:
- Default MitM Gate Intervention: Every external action or file command proposed by an MCP tool or search query is intercepted by the MitM Gate, prompting you for manual confirmation
[y/N]. No command runs silently.
- User-Configured Autonomy: To maintain a smooth developer workflow, you can configure permission levels and grant autonomy (auto-whitelist) to specific trusted MCP tools or commands, bypassing repetitive prompts without restricting tools in a limiting sandbox.
- Proxy-Free Querying: All search queries are sent directly from your local machine to Brave or DuckDuckGo. No intermediate Orbika servers process, store, or monitor your search context.
C. Licensing Telemetry Policy
To validate paid subscription tiers, the application performs a minimal administrative check:
- Strict Separation of Concerns: Licensing telemetry is entirely decoupled from AI inference. Your prompts, code files, and conversation history never leave your machine.
- Minimal Payload: Telemetry is strictly limited to subscription status validation (hashed license key + local hardware hash) performed once a month.
- 30-Day Offline Grace Period: If your system is disconnected from the network, Orbika Lucid continues to run uninterrupted for up to 30 days before requiring the next license check.
D. Protection of Sensitive Documents (Researchers, Journalists & Students)
For non-technical users utilizing Orbika Lucid to read large PDF files, analyze journals, or construct visual cognitive mindmaps:
- Intellectual Property Integrity: All parsed document text, uploaded PDFs, vector databases (RAG), and mindmap metadata are processed and saved locally. No content extracts are uploaded to external APIs.
- Physical Verification: You can verify this by inspecting the application's local database directory at
~/.config/Orbika/Orbika Lucid/. All vector indexes and cached document database files are stored strictly there.
- No Data Harvesting: Because there are no cloud relays, no external entity can harvest your research manuscripts, journalist sources, or student study logs to train corporate AI models.
E. Secure Crash Reporting Policy
To help us diagnose software issues rapidly without exposing your personal information, we employ a secure crash reporting protocol:
- Local RSA Encryption: The crash traceback log and your registered email address are cryptographically encrypted using our Public Key directly on your local device before transmission.
- Transparent Consent: Crash reports are never sent silently. When a critical failure occurs, a dialog discloses the raw error log details and requires your explicit approval before transmission.
- Secure Server Vault: Once received, reports are stored in our web server database in an encrypted state and can only be decrypted offline by our administrator using a physically isolated Private Key.
Base de Conocimientos (Wiki)
Documentación técnica oficial y referencias para el ecosistema Orbika Lucid y CoLucid CLI (ask).
1. Instalación Básica (Linux)
Orbika Lucid se distribuye como un paquete ejecutable portable .AppImage para Linux, lo que facilita su ejecución sin preocuparse por las dependencias.
# Otorgar permisos de ejecución
chmod +x OrbikaLucid-x86_64.AppImage
# Iniciar la aplicación
./OrbikaLucid-x86_64.AppImage
2. Uso de CoLucid CLI (ask)
Una vez instalado, puede llamar al comando ask directamente desde su terminal sin abrir la interfaz gráfica (GUI).
Consulta Directa
ask "¿cómo verificar la lista de puertos activos en Ubuntu?"
Diagnóstico de Errores (Redirección/Piping)
Redirija los logs de error para obtener un diagnóstico rápido:
cat /var/log/syslog | tail -n 50 | ask "¿por qué falló el inicio del servicio docker?"
3. Gestión de Seguridad (MitM Gate)
El sistema MitM Gate bloquea automáticamente los comandos sospechosos. Para añadir comandos a la lista blanca (whitelist), edite el archivo settings.json:
{
"security": {
"whitelist": ["systemctl restart nginx", "ufw status"]
}
}
4. Audit Vault (Registro de Auditoría)
Cada confirmación manual del usuario [y/N] se firma digitalmente con HMAC y se registra de forma inmutable en storage/audit_vault.json para el cumplimiento de las auditorías de TI corporativas.
5. Verificación de Zero-Trust y Política de Licencias
Orbika Lucid opera bajo un estricto modelo de soberanía de datos. Para admitir integraciones avanzadas como búsquedas web, servidores MCP y suscripciones comerciales, las siguientes pautas definen cómo garantizamos la seguridad zero-trust:
A. Auditoría de Aislamiento de Red
Todas las llamadas de inferencia de LLM se manejan localmente. Puede verificar esto desconectando su dispositivo de Internet o utilizando analizadores de paquetes (como Wireshark) durante un chat. El software se comunica estrictamente a través de puertos locales (localhost 127.0.0.1:11434).
B. Búsquedas Web (Brave/DDG) y Servidores MCP
Al habilitar motores de búsqueda (Brave Search / DuckDuckGo) o integrar servidores de Model Context Protocol (MCP) externos:
- Intervención de MitM Gate por Defecto: Cada acción propuesta por una herramienta MCP o consulta de búsqueda es interceptada por el MitM Gate, solicitando su aprobación manual
[y/N]. Ningún comando se ejecuta silenciosamente.
- Autonomía Configurable por el Usuario: Para mantener un flujo de trabajo fluido, puede otorgar autonomía (aprobación automática) a herramientas MCP o comandos específicos de confianza, eliminando solicitudes repetitivas sin necesidad de un sandbox restrictivo.
- Conexión sin Intermediarios: Las consultas se envían directamente desde su cliente local a Brave o DuckDuckGo. Ningún servidor corporativo de Orbika enruta o recopila sus datos.
C. Política de Telemetría de Licencias
Para validar las suscripciones comerciales activas, la aplicación realiza una verificación administrativa mínima:
- Separación Estricta de Funciones: La telemetría de licencias está totalmente desacoplada de la inferencia de IA. Sus consultas, código fuente e historial de chat nunca salen de su máquina.
- Carga Útil Mínima: La telemetría se limita estrictamente a la validación de la licencia (clave hash + hash de hardware local) una vez al mes.
- Periodo de Gracia sin Conexión de 30 Días: Si su dispositivo no tiene internet, Orbika Lucid sigue funcionando sin interrupción hasta por 30 días antes de requerir la próxima verificación de licencia.
D. Protección de Documentos Sensibles (Investigadores, Periodistas y Estudiantes)
Para usuarios no técnicos que utilizan Orbika Lucid para leer archivos PDF grandes, analizar diarios o construir mapas mentales cognitivos:
- Integridad de la Propiedad Intelectual: Todo el texto del documento procesado, los PDF cargados, las bases de datos vectoriales (RAG) y los metadatos del mapa mental se procesan y guardan localmente. Ningún extracto se sube a la nube.
- Verificación Física: Puede verificar esto inspeccionando el directorio de la base de datos local en
~/.config/Orbika/Orbika Lucid/. Todos los índices de vectores y archivos se guardan exclusivamente allí.
- Sin Cosecha de Datos: Debido a que no hay servidores intermedios, ninguna corporación externa puede recopilar sus manuscritos, fuentes periodísticas o registros de estudio para entrenar modelos de IA comerciales.
E. Política de Informe de Errores Seguro
Para ayudarnos a diagnosticar problemas de software rápidamente sin exponer su información personal, empleamos un protocolo de informe de errores seguro:
- Cifrado RSA Local: El registro de errores (traceback) y su dirección de correo electrónico registrada se cifran criptográficamente utilizando nuestra Clave Pública directamente en su dispositivo local antes de la transmisión.
- Consentimiento Transparente: Los informes de errores nunca se envían de forma silenciosa. Cuando ocurre una falla crítica, un cuadro de diálogo muestra los detalles del registro de errores y requiere su aprobación explícita antes del envío.
- Bóveda de Servidor Segura: Una vez recibidos, los informes se almacenan en la base de datos de nuestro servidor web en un estado cifrado y solo el administrador puede descifrarlos fuera de línea utilizando una Clave Privada físicamente aislada.
Base de Connaissances (Wiki)
Documentation technique officielle et références pour l'écosystème Orbika Lucid et CoLucid CLI (ask).
1. Installation de Base (Linux)
Orbika Lucid est distribué sous forme de fichier autonome .AppImage pour Linux, permettant une exécution portable et sans soucis de dépendances.
# Accorder les permissions d'exécution
chmod +x OrbikaLucid-x86_64.AppImage
# Lancer l'application
./OrbikaLucid-x86_64.AppImage
2. Utilisation de CoLucid CLI (ask)
Une fois installé, vous pouvez appeler la commande ask directement depuis votre terminal sans lancer l'interface graphique (GUI).
Question Directe
ask "comment vérifier la liste des ports actifs sous Ubuntu?"
Diagnostic d'Erreur (Piping)
Redirigez les logs d'erreurs pour obtenir un diagnostic immédiat :
cat /var/log/syslog | tail -n 50 | ask "pourquoi le service docker a-t-il échoué à démarrer?"
3. Gestion de la Sécurité (MitM Gate)
Le système MitM Gate intercepte automatiquement les commandes inhabituelles. Pour ajouter des commandes à la liste blanche (whitelist), modifiez le fichier settings.json :
{
"security": {
"whitelist": ["systemctl restart nginx", "ufw status"]
}
}
4. Audit Vault
Chaque approbation de commande accordée par l'utilisateur [y/N] est enregistrée avec une signature HMAC sécurisée dans le fichier storage/audit_vault.json pour les audits informatiques en entreprise.
5. Vérification Zero-Trust et Politique de Licence
Orbika Lucid fonctionne sur un modèle strict de souveraineté des données. Pour prendre en charge les intégrations avancées telles que la recherche web, les serveurs MCP et les abonnements commerciaux, les directives suivantes définissent la sécurité zero-trust :
A. Audit de l'Isolation Réseau
Toutes les requêtes LLM sont traitées localement. Vous pouvez le vérifier en déconnectant votre appareil d'Internet ou en analysant les paquets réseau (comme Wireshark). L'application communique uniquement via les ports locaux (localhost 127.0.0.1:11434).
B. Recherches Web (Brave/DDG) et Serveurs MCP
Lors de l'activation des moteurs de recherche (Brave Search / DuckDuckGo) ou de l'intégration de serveurs MCP (Model Context Protocol) externes :
- Intervention du MitM Gate par Défaut : Chaque action externe ou commande de fichier proposée par un outil MCP ou une recherche est interceptée par le MitM Gate, vous demandant une validation manuelle
[y/N]. Aucun processus ne s'exécute silencieusement.
- Autonomie Configurable par l'Utilisateur : Pour préserver la fluidité de votre flux de travail, vous pouvez configurer des niveaux de permission et accorder l'autonomie (approbation automatique) à des outils MCP ou commandes spécifiques, évitant les invites répétitives sans restreindre l'outil dans un sandbox bloquant.
- Connexion Directe sans Intermédiaire : Les requêtes de recherche sont envoyées directement depuis votre machine locale vers Brave ou DuckDuckGo. Aucun serveur Orbika ne stocke ou ne surveille vos requêtes.
C. Politique de Télémétrie des Licences
Pour valider les abonnements payants, l'application effectue une vérification administrative minimale :
- Séparation Stricte des Données : La télémétrie de licence est entièrement séparée de l'intelligence artificielle. Vos prompts, fichiers de code et historique de discussion ne quittent jamais votre machine.
- Payload Minimal : La télémétrie est limitée à la validation de la licence (clé de licence hachée + identifiant matériel haché) une fois par mois.
- Fonctionnement Hors Ligne (30 jours) : Si votre système est hors ligne, Orbika Lucid continue de fonctionner normalement pendant 30 jours avant de nécessiter un nouveau contrôle de licence.
D. Protection des Documents Sensibles (Chercheurs, Journalistes & Étudiants)
Pour les utilisateurs non techniques qui utilisent Orbika Lucid pour lire de grands fichiers PDF, analyser des journaux ou construire des cartes cognitives visuelles :
- Intégrité de la Propriété Intellectuelle : Tous les textes extraits, les PDF importés, les bases de données vectorielles (RAG) et les métadonnées de cartes cognitives sont stockés localement. Aucun extrait n'est envoyé sur le cloud.
- Vérification Physique : Vous pouvez le vérifier en inspectant le dossier de base de données locale sous
~/.config/Orbika/Orbika Lucid/. Tous les index de vecteurs et caches y sont enregistrés exclusivement.
- Pas de Collecte de Données : Comme il n'y a pas de serveurs tiers, aucune entité externe ne peut collecter vos manuscrits de recherche, sources journalistiques ou notes d'études pour entraîner des modèles d'IA.
E. Politique de Rapport de Crash Sécurisé
Pour nous aider à diagnostiquer rapidement les problèmes logiciels sans exposer vos informations personnelles, nous utilisons un protocole de rapport de crash sécurisé :
- Chiffrement RSA Local : Le journal d'erreurs (traceback) et votre adresse e-mail enregistrée sont chiffrés cryptographiquement à l'aide de notre clé publique directement sur votre appareil local avant transmission.
- Consentement Transparent : Les rapports de crash ne sont jamais envoyés silencieusement. En cas de défaillance critique, une boîte de dialogue affiche les détails du journal d'erreurs et requiert votre approbation explicite avant l'envoi.
- Coffre-fort Serveur Sécurisé : Une fois reçus, les rapports sont stockés dans la base de données de notre serveur web dans un état chiffré et ne peuvent être déchiffrés hors ligne par notre administrateur qu'à l'aide d'une clé privée physiquement isolée.
ナレッジベース (Wiki)
Orbika Lucid エコシステムおよび CoLucid CLI (ask) の公式技術ドキュメントとリファレンスです。
1. 基本インストール (Linux)
Orbika Lucid は、Linux オペレーティングシステム向けにポータブルな .AppImage パッケージとして配布されており、依存関係なしで実行できます。
# 実行権限を付与する
chmod +x OrbikaLucid-x86_64.AppImage
# アプリケーションを実行する
./OrbikaLucid-x86_64.AppImage
2. CoLucid CLI (ask) の使い方
インストール後、GUI を起動せずにターミナルから直接 ask コマンドを呼び出すことができます。
ダイレクトプロンプト
ask "Ubuntuでアクティブなポートのリストを確認する方法は?"
エラー診断 (パイプライン)
エラーログを直接パイプして即座に診断します:
cat /var/log/syslog | tail -n 50 | ask "dockerサービスが起動しなかった理由は?"
3. セキュリティ管理 (MitM Gate)
MitM Gate システムは不審なコマンドを自動的にインターセプトします。ホワイトリストにコマンドを追加するには、ローカルの settings.json ファイルを編集します:
{
"security": {
"whitelist": ["systemctl restart nginx", "ufw status"]
}
}
4. Audit Vault (監査ログ)
ユーザーによって承認されたすべてのコマンド実行 [y/N] は、改ざん防止の HMAC 署名付きで storage/audit_vault.json に記録され、企業の IT 監査に利用できます。
5. ゼロトラスト検証とライセンスポリシー
Orbika Lucid は厳格なデータ主権モデルに基づいて動作します。ウェブ検索、MCP(Model Context Protocol)サーバー、コマーシャルサブスクリプションなどの高度な機能をサポートするため、以下のゼロトラストセキュリティガイドラインを適用しています。
A. ネットワークの隔離監査
すべてのLLM推論コールはローカルで処理されます。チャット中にインターネット接続を切断するか、パケットアナライザー(Wiresharkなど)を使用することで簡単に検証できます。アプリケーションはローカルポート(localhost 127.0.0.1:11434)経由のみで通信します。
B. ウェブ検索 (Brave/DDG) と MCP サーバーの信頼モデル
オンライン検索(Brave Search / DuckDuckGo)を有効に、または外部MCPサーバーを統合する場合:
- デフォルトの MitM Gate 介入: MCPツールまたは検索クエリによって提案されるすべての外部アクションおよびファイルコマンドは、MitM Gateによってインターセプトされ、ユーザーに手動承認
[y/N] を求めます。裏で勝手にコマンドが実行されることはありません。
- ユーザー設定可能な自律性: 開発ワークフローを快適に保つため、信頼できる特定のMCPツールやコマンドに対して自律性(自動承認/ホワイトリスト)を設定し、制限的なサンドボックスでツールの機能を損なうことなく、繰り返しのポップアップ承認をバイパスできます。
- プロキシフリーの直接接続: 検索クエリはローカルクライアントから直接 Brave または DuckDuckGo に送信されます。中間にOrbikaのサーバーが介在してクエリを監視、保存、処理することはありません。
C. ライセンス検証のテレメトリーポリシー
有料サブスクリプションプランを検証するため、アプリケーションは必要最小限の管理チェックを行います。
- 関心事の厳格な分離: ライセンス認証テレメトリーは、AI推論から完全に切り離されています。プロンプト、ソースコード、会話履歴が外部に送信されることは決してありません。
- 最小限のペイロード: テレメトリーは、月に1回行われるサブスクリプションステータスの検証(ハッシュ化されたライセンスキー + ハッシュ化されたハードウェアID)のみに厳密に制限されています。
- 30日間のオフライン猶予期間: デバイスがオフラインの場合でも、次のライセンスチェックが必要になるまで、Orbika Lucid は最大30日間制限なく動作し続けます。
D. 機密ドキュメントの保護 (研究者・ジャーナリスト・学生向け)
PDFファイルの読込、学術文献の分析、またはビジュアルなマインドマップ of 作成機能を利用する非技術系ユーザー向け:
- 知的財産の保護: 解析されたドキュメントテキスト、読み込まれたPDF、ベクトルデータベース(RAG)、およびマインドマップのメタデータはすべてローカルで処理・保存されます。外部APIにドキュメントがアップロードされることはありません。
- 物理的な検証: アプリケーションのローカルデータベースディレクトリ(Linuxでは
~/.config/Orbika/Orbika Lucid/)を確認することで検証できます。すべてのベクトルインデックスおよびキャッシュファイルがそこにのみ保存されています。
- AI学習へのデータ転用の遮断: クラウド連携がないため、企業のAIモデル学習用データとして研究論文、取材ソース、学生の研究ログなどが収集されるリスクはゼロです。
E. セキュアなクラッシュレポート・ポリシー
個人情報を公開することなくソフトウェアの問題を迅速に診断するために、セキュアなクラッシュレポート・プロトコルを採用しています。
- ローカルRSA暗号化: クラッシュのトレースバックログと登録済みのメールアドレスは、送信前にローカルデバイス上で直接公開キーを使用して暗号化されます。
- 透明な同意プロセス: クラッシュレポートがバックグラウンドで無断送信されることはありません。致命的なエラーが発生した場合、詳細なログを開示するダイアログが表示され、送信前にユーザーの明示的な承認を要求します。
- セキュアなサーバー保管: 受信したレポートは、Webサーバーのデータベースに暗号化された状態で保存され、サーバーから物理的に隔離された秘密キーを使用して管理者のみがオフラインで復号できます。
مركز المعرفة (Wiki)
الوثائق والمراجع التقنية الرسمية لاستخدام نظام Orbika Lucid وبيئة CoLucid CLI (ask).
1. التثبيت الأساسي (Linux)
يتم توزيع Orbika Lucid كحزمة محمولة .AppImage لأنظمة تشغيل Linux. يتيح لك ذلك التشغيل المباشر دون قلق بشأن الاعتماديات البرمجية.
# منح صلاحية التنفيذ
chmod +x OrbikaLucid-x86_64.AppImage
# تشغيل التطبيق
./OrbikaLucid-x86_64.AppImage
2. استخدام CoLucid CLI (ask)
بعد التثبيت، يمكنك استدعاء أمر ask مباشرة من موجه أوامر الطرفية الخاصة بك دون الحاجة لفتح الواجهة الرسومية (GUI).
السؤال المباشر (Direct Prompt)
ask "كيفية التحقق من المنافذ النشطة في أوبونتو؟"
تشخيص الأخطاء (Piping)
قم بتمرير سجلات الأخطاء مباشرة للتشخيص الفوري والسريع:
cat /var/log/syslog | tail -n 50 | ask "لماذا فشل تشغيل خدمة Docker؟"
3. إدارة الأمن (MitM Gate)
يقوم نظام MitM Gate تلقائيًا باعتراض الأوامر غير المعتادة. لتسجيل الأوامر في القائمة البيضاء، قم بتحرير ملف الإعدادات المحلي settings.json:
{
"security": {
"whitelist": ["systemctl restart nginx", "ufw status"]
}
}
4. سجل التدقيق (Audit Vault)
يتم تسجيل كل موافقة أمر يمنحها المستخدم [y/N] بتوقيع HMAC مشفر غير قابل للتلاعب في ملف storage/audit_vault.json لأغراض التدقيق لمؤسسات تقنية المعلومات.
٥. التحقق من أمان Zero-Trust وسياسة الترخيص
يعمل نظام Orbika Lucid وفق نموذج صارم لسيادة البيانات. لدعم التكاملات المتقدمة مثل البحث عبر الويب، وخوادم بروتوكول سياق النموذج (MCP)، والاشتراكات التجارية، توضح الإرشادات التالية كيفية ضمان أمان zero-trust:
أ. تدقيق عزل الشبكة
يتم التعامل مع جميع طلبات استدعاء LLM محليًا بالكامل. يمكنك التحقق من ذلك بسهولة عن طريق فصل جهازك عن الإنترنت أو استخدام أدوات تحليل حركة الشبكة (مثل Wireshark) أثناء المحادثة. يتصل التطبيق بشكل صارم عبر منافذ المضيف المحلي (localhost 127.0.0.1:11434).
ب. عمليات البحث على الويب (Brave/DDG) وتكامل خوادم MCP
عند تفعيل محركات البحث عبر الإنترنت (Brave Search أو DuckDuckGo) أو دمج خوادم بروتوكول MCP الخارجية:
- تدخل بوابة الأمن (MitM Gate) افتراضيًا: يتم اعتراض كل إجراء خارجي أو أمر للملفات مقترح بواسطة أداة MCP أو استعلام بحث بواسطة MitM Gate، مما يطلب منك موافقة يدويًا
[y/N]. لا يتم تشغيل أي أمر في الخلفية بصمت.
- صلاحيات الاستقلالية القابلة للتكوين: للحفاظ على سلاسة سير عمل المطور، يمكنك تكوين مستويات الأذونات ومنح الاستقلالية (الموافقة التلقائية) لأدوات MCP أو أوامر معينة موثوقة، مما يتجنب المطالبات المتكررة دون عزل الأدوات في حاويات تقيد وظائفها.
- اتصال مباشر بدون وسطاء: تُرسل استعلامات البحث مباشرة من جهازك المحلي إلى Brave أو DuckDuckGo. لا تقوم خوادم شركة Orbika المركزية بتوجيه أو تخزين أو مراقبة سياق البحث الخاص بك.
ج. سياسة تيليميتري التراخيص والاشتراكات
للتحقق من صلاحية الاشتراكات المدفوعة، يقوم التطبيق بإجراء فحص إداري بسيط للغاية:
- الفصل التام للبيانات: يتم فصل عمليات التحقق من الترخيص تمامًا عن عمل الذكاء الاصطناعي. لا تغادر نصوص المحادثات، أو ملفات الأكواد، أو سجلات الأوامر جهازك أبدًا.
- أدنى حجم للبيانات المرسلة: يقتصر التيليميتري بشكل صارم على التحقق من حالة الاشتراك (مفتاح الترخيص المشفر + بصمة قطع الكمبيوتر المشفرة) مرة واحدة شهريًا.
- فترة سماح دون اتصال بالشبكة لمدة ٣٠ يومًا: في حال كان جهازك غير متصل بالإنترنت، يستمر تطبيق Orbika Lucid في العمل دون أي انقطاع لمدة تصل إلى ٣٠ يومًا قبل أن يطلب فحص الترخيص التالي.
د. حماية المستندات الحساسة (الباحثين، الصحفيين، والطلاب)
للمستخدمين غير التقنيين الذين يستخدمون Orbika Lucid لقراءة ملفات PDF الضخمة، أو تحليل الأوراق البحثية، أو إنشاء خرائط ذهنية إدراكية:
- سلامة الملكية الفكرية: يتم معالجة وحفظ جميع نصوص المستندات المستخرجة، وملفات PDF المرفوعة، وقواعد البيانات المتجهة (RAG)، والبيانات الوصفية للخرائط الذهنية محليًا بالكامل. لا يتم رفع أي محتوى إلى السحابة.
- التحقق المادي: يمكنك التحقق من ذلك عن طريق فحص دليل قاعدة البيانات المحلية للتطبيق في
~/.config/Orbika/Orbika Lucid/. يتم تخزين جميع الفهارس المتجهة وملفات ذاكرة التخزين المؤقت هناك فقط.
- منع جمع البيانات للتدريب: نظرًا لعدم وجود اتصالات سحابية، لا يمكن لأي جهة خارجية جمع مسودات أبحاثك، أو مصادرك الصحفية، أو سجلات دراسة الطلاب لتدريب نماذج الذكاء الاصطناعي التجارية.
هـ. سياسة تقارير الأعطال الآمنة (Secure Crash Reporting)
لمساعدتنا في تشخيص مشكلات البرامج بسرعة دون الكشف عن معلوماتك الشخصية، نستخدم بروتوكولًا آمنًا للإبلاغ عن الأعطال:
- تشفير RSA محلي: يتم تشفير سجل الأخطاء (traceback) وعنوان بريدك الإلكتروني المسجل تشفيرًا مشفرًا باستخدام المفتاح العام الخاص بنا مباشرة على جهازك المحلي قبل الإرسال.
- موافقة شفافة: لا يتم إرسال تقارير الأعطال بصمت أبدًا. عند حدوث عطل حرج، يعرض مربع حوار تفاصيل سجل الأخطاء ويطلب موافقتك الصريحة قبل الإرسال.
- مخزن خادم آمن: بمجرد استلام التقارير، يتم تخزينها في قاعدة بيانات خادم الويب الخاص بنا في حالة مشفرة، ولا يمكن فك تشفيرها إلا في وضع عدم الاتصال بواسطة المسؤول لدينا باستخدام مفتاح خاص معزول ماديًا عن الخادم.