# Privacy and scientific-claim review

## Privacy result

The study workspace contains no station coordinate, street/address, device identifier, user identity, credential, private IP address, internal hostname or authentication record.

Safeguards applied:

- analysis used a preserved BSON dump restored to a network-isolated tmpfs MongoDB container;
- the operational database was not contacted;
- telemetry export excludes `device`, device ID and station-location fields;
- automation export removes Mongo object IDs and `assessment.telemetry_device_id`;
- web users, authentication audit, device registry, policy identifiers and exact location were not exported;
- the post-study shadow log remains in its source repository because it contains identifiers; only its count, time bounds and hash are inventoried;
- public-safe candidate metrics use the alias `station_primary` implicitly and contain no precise location;
- text-pattern scanning of the completed workspace found no private IP, coordinate pair, 24-character object ID, Windows user path or token-like assignment.

The controlled inputs remain research derivatives, not publication files. Only `public-safe/` artifacts are candidates for later editorial review.

## Scientific claim matrix

| Candidate claim | Status | Boundary |
| --- | --- | --- |
| The station record is substantially complete for 20 Jan-10 Mar | Supported | 99.256% occupied minute-bin coverage; nine gaps over five minutes; maximum gap 6,832.394 s. |
| The station recorded a sharp pressure fall during Kristin | Supported | −12.288 hPa peak six-hour fall within the official window. This is a local sensor observation. |
| Kristin caused the exact station trace | Not established | Temporal alignment and synoptic plausibility do not constitute a causal attribution experiment. |
| The station recorded repeated low-pressure pulses in the Leonardo/Marta sequence | Supported | Multiple frozen-threshold episodes occur inside the 3-8 February comparison window. |
| The Nils/Oriana window contains the strongest 12-hour fall among the five defined windows | Supported | −20.223 hPa in the station-derived window metrics. |
| Ingrid was a major local pressure episode under the frozen method | Not supported | It does not cross the discovery thresholds, though its −8.855 hPa six-hour fall is more negative than all selected controls. |
| The 5-7 March warning period was a major local pressure episode | Not supported | Peak six-hour fall is −2.866 hPa and no discovery episode overlaps the window. |
| EDS measured rainfall or wind from these systems | Unsupported | The station fields in scope contain no rain gauge or anemometer measurement. |
| EDS forecasts were correct for these storms | Unsupported | No preserved as-served output overlaps the event windows. |
| March 10 automation outputs describe the 5-7 March period | False | The first preserved decision is 10 March at 01:57:41 UTC. |
| Current models reproduce what operators saw | False unless explicitly labeled retrospective | Later model artifacts and configurations differ and include overlapping training/calibration data. |
| This sequence validates regional storm severity or public-warning thresholds | Unsupported | EDS is one local station; official sources provide regional context. |

## Time claim boundary

Firmware documentation says station timestamps are produced from NTP-synchronized UTC at acquisition when available. Core ingestion preserves that timestamp but can substitute server UTC when a timestamp is absent or cannot be parsed. The stored record has no per-row flag distinguishing those paths. Therefore the study uses the timestamps as operational reconstruction time, supported by the one-minute cadence, but not as independently certified precision timing.

Portugal continental remained on WET (UTC+0) during the entire study interval, so local civil-hour labels and UTC coincide. All machine-readable outputs nevertheless remain explicitly UTC.

## Review requirements

Before publication, a human reviewer must verify:

1. that every named-event use remains tied to its official source;
2. that figures label event windows as comparison windows, not exact local arrivals;
3. that forecast/model language never upgrades retrospective evidence into historical output;
4. that the March negative case and Ingrid threshold miss remain visible;
5. that no controlled input is copied into a public web tree;
6. that public-safe figures and metrics receive independent scientific and editorial sign-off.

