Internal Border

Cognitive Security

Internal Border

Why we believe the medium is the boundary, and why the machine sees through our private theories.

The Architecture of the “Safe” Box

I once sent a scathing critique of a client’s choice in office wallpaper-I believe I called it “purgatorial beige”-to the client herself. It was meant for my sister. The mistake wasn’t just a technical slip of the thumb; it was a fundamental failure of my own internal architecture.

I had convinced myself that because I was typing into a different “box” on my phone, the sentiment was safely partitioned. I believed the medium was the boundary. I was wrong, of course.

The information doesn’t care about the container, and neither does the person who eventually reads it. We spend half our lives building these imaginary walls, convinced that if we just change the delivery method, the payload becomes harmless.

We are currently doing the exact same thing with artificial intelligence, and we’re doing it with a level of earnestness that borders on the religious. We have entered an era of “Metabolic Translation.”

This is the process where a professional takes a sensitive document-a contract, a medical record, a strategic pivot-and decides that uploading the actual file would be an unforgivable breach of security.

24 Minutes

Manual Summarization Tax

Instead of uploading, professionals spend nearly half an hour manually re-encoding sensitive data into prompt boxes.

So, instead, they sit there for and manually type a summary of that document into the prompt. The story we tell ourselves is that a summary is not the file.

We believe that by passing the information through the filter of our own consciousness, we are somehow laundering the data, stripping it of its “lethality” before it hits the cloud. It is a private theory shaped exactly like our workload: it allows us to get the help we need from the machine without having to admit we are breaking the rules.

The Ethics of the Privacy Screen

Take Marion, an HR director I spoke with last month. Marion is the kind of person who uses a privacy screen on her laptop even when she’s working from home. She is deeply ethical and perpetually exhausted.

She had a salary grid that was a total mess-14 people across three departments, with pay gaps that looked like they had been decided by a random number generator. She needed the AI to help her draft a communication plan to normalize these ranges.

Original Format (.csv)

“Unforgivable breach of security.”

“Marion-Flavored-Prose”

“team of twelve, three at senior band, one significantly above range…”

“I have behaved correctly.”

She would never, under any circumstances, upload that spreadsheet. She told me this with the pride of a soldier who had refused to give up the codes. Instead, she spent her evening typing: “team of twelve, three at senior band, one significantly above range following a counter-offer, the gap is causing a problem.”

She pressed enter and felt she had behaved correctly. She felt she had protected her people.

In reality, Marion had just performed a high-fidelity semantic transfer. She hadn’t “protected” the data; she had simply converted it from a `.csv` format into a “Marion-flavored-prose” format. To a Large Language Model, the difference is negligible.

The model doesn’t “read” a file the way we do; it ingests tokens and maps relationships. Whether the input is a cell in a table or a sentence in a paragraph, the resulting vector-the mathematical representation of that information-is largely the same.

Marion’s “summary” contained the exact same corporate vulnerabilities as the original file. The only difference was that she had wasted twenty minutes of her life re-encoding it.

This distinction has no technical basis, yet it possesses enormous psychological power. Nobody sold us this idea. OpenAI didn’t tell us that summaries are “safer” than uploads. We invented this rule ourselves because it lets us keep working.

It’s a cognitive buffer. If we upload the file, we feel like we’ve “handed over the keys.” If we type the description, we feel like we’re just “talking to a colleague.”

The Purgatorial Safety Zone

The tools have absolutely no interest in correcting this delusion. A user who has found a private rule that makes them comfortable is a user who has stopped asking the vendor difficult questions.

If you believe your “summary” is safe, you stop demanding end-to-end encryption. You stop asking where the logs go. You stop worrying about whether your data is being used to train the next iteration of the model. You’ve found your “purgatorial beige” safety zone, and the vendor is more than happy to let you sit there.

My old colleague Helen J., an assembly line optimizer who spent stripping the fat out of manufacturing processes, once watched a team of engineers manually re-entering data from one system to another because the official integration was “too risky.”

“Efficiency is the first thing we sacrifice to the god of plausible deniability.”

– Helen J., Assembly Line Optimizer

She was right. We are sacrificing our time and our clarity for a feeling of safety that doesn’t exist. When we translate a document into a summary, we often introduce errors. We smooth over the very outliers the AI needs to see to be helpful.

We create a “shadow version” of the truth that is just as exposed but half as useful. We are working harder to be less secure.

The tragedy of the “summary delusion” is that it’s born from a good impulse. Professionals like Marion care about their data. They feel the weight of their responsibility.

But under sustained pressure-the need to produce more, faster, with better insights-people do not stop doing the risky thing. They simply build a small private theory that makes the risk acceptable. This is how thoughtful, ethical professionals end up doing exactly what they would advise a junior colleague against.

We need to stop negotiating with our own judgment. The energy we spend deciding which parts of a document are “safe” to summarize is a tax on our intellect. It’s a drain on our “metabolic” resources. If you are using a tool that requires you to lie to yourself about what you’re sharing, you are using the wrong tool.

The Physics of the Connection

This is where the architecture of the channel matters more than the behavior of the user. When the channel itself is protected, the need for these mental gymnastics disappears.

You don’t have to decide if a “summary” is safer than a “file” if the infrastructure ensures that neither can be seen, stored, or used against you. When you use

Tunneltunnel,

the privacy isn’t a rule you have to remember; it’s a feature of the physics of the connection.

👤

Identity Stripped

🔐

Local Encryption

🚫

Zero Server Logs

When the infrastructure is actually secure, you get your Saturdays back. You stop being a “translator” for your own data and start being a user again. You can upload the salary grid. You can paste the messy contract.

You can stop the 24-minute ritual of typing “team of twelve, three at senior band…” and just get the answer you need.

We are currently living in a world of “leaky containers,” and we’ve responded by trying to carry the water in our cupped hands, thinking that’s somehow better because we’re the ones holding it. But our hands are porous. The water still hits the floor. The only way to stop the leak isn’t to change how we hold the water; it’s to change the floor.

I still feel a pang of anxiety every time I send a text message that contains a name or a specific detail. That “purgatorial beige” incident left a scar. It reminded me that there is no such thing as a “safe” box if the box is connected to the world.

But in my professional life, I’ve realized that the only way to be truly ethical is to stop relying on my own ability to “summarize” my way out of a security breach.

We have to stop pretending that our “careful descriptions” are invisible to the machines we feed them to. They aren’t. The machine sees the pattern, not the prose. It sees the 4 senior members and the 2 outliers regardless of whether they are in a cell or a sentence.

Our only real protection is to use systems that don’t look at the data at all. Until then, we’re just typing into the void, hoping our private theories are enough to keep the walls standing.

They won’t be. The only wall that matters is the one built into the code, not the one built into our justifications.