whiskers-guard

What Jev is asked about each message, and how the answer becomes a Verdict. Every message, in either direction, gets two questions in one request: is it entirely suitable for a child of the profile's age (a yes-or-no probability), and what is it mainly about (a choice of nine topics). A message is allowed only if it is "ordinary" and Jev is at least 85% sure it is suitable (whiskers_judge::MIN_SUITABLE).

Two kinds of refusal exist. Most are off-limits topics: the cat steers somewhere else. What the child says about being hurt or unsafe, or being asked to keep a secret from the parents, is a different kind: the cat sends the child to a grown-up, and the parents' view puts it first.

The tablet never holds the Jev key. RemoteGuard asks whiskersd (on a machine the operator runs, over a private network), which does the call.

FileWhat
src/lib.rsRe-exports the questions, topics and decide from whiskers-judge, where the whole policy lives as pure code.
src/remote.rsRemoteGuard, the Guard the tablet uses.
tests/remote.rsThe client against stub servers.