Offline-first architecture
Two independent signatures on price documents
ADR-0008: a cost model or price table is accepted only with two signatures from two separate key sets; the ordinary single-signature check refuses these document types. This is enforced in code and tests with throwaway test keys. The key ceremony (who holds the keys, the second signer, offline custody) has not been done, so no real price can be published. ADR-0009 (tentative) sketches two independent custodians in separate legal entities with their own offline hardware keys; none exists.
Built in the repository (checked files or tested library code; not a product you can run yet)
What to plan for
- Ceremony not done
- Second signer not chosen
- Losing both keys of one side stops publishing
What the catalog lists
Planned items that match this topic (keyword match; read each as a pointer):
- Quarterly cost model as signed data LIC-0052
- Flat fee calculator: the quarter's cost split among paying members LIC-0073
- One flat quarterly fee for every product LIC-0061
- Early members are rewarded by their own bill falling LIC-0062
- Your bill has dropped X percent LIC-0063
- Bill change refuses an unsound history LIC-0064
- No per-member fee ceiling LIC-0065
- Mock cost model can never look real LIC-0056
- Cost model expires with its quarter LIC-0057
- Price table derived from a final cost model LIC-0058
- Quarterly transparency view for the website LIC-0059
- Two independent signatures on cost and price documents LIC-0066
Honesty note
Everything listed is a plan or a design principle. No app is released and nothing is audited or certified.