Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Catalog section · SEC

Packaging security model (ADR-0006)

15 planned items in Security, Audit & Privacy.

True removal: a build holds nothing for elements outside its spec

SEC-0042 Planned Lite and Pro Core

A package contains no code, assets, migrations or data for elements that are not in its spec or entitlement; the closure of the spec is the whole build

Depends on: SEC-0001

Hiding by flag does not count as removal

SEC-0043 Planned Lite and Pro Core

A feature switched off by a setting or flag but still shipped is treated as present; only absence from the build counts

Depends on: SEC-0001

Absence test per profile: files

SEC-0044 Planned Lite and Pro Core

For each tested profile the engine checks that files of elements outside the closure are not in the package

Depends on: SEC-0001

Absence test per profile: commands and menus refuse

SEC-0045 Planned Lite and Pro Core

For each tested profile every operation of an element outside the enabled set is refused and no menu entry exists for it

Depends on: SEC-0001

Absence test per profile: database schema lacks removed tables

SEC-0046 Planned Lite and Pro Core

For each tested profile a database created by the build contains no tables of elements outside the closure

Depends on: SEC-0001

Signed everything: builds, updates, entitlements, catalog and price documents

SEC-0047 Planned Lite and Pro Core

Every artifact that changes what the app does or what it may do is signed with Ed25519 and verified before use

Depends on: SEC-0001

Signature is mandatory, no skip path

SEC-0048 Planned Lite and Pro Core

A missing, empty or malformed hash or signature is an error, never a reason to skip verification

Depends on: SEC-0001

No demo or default keys in any build

SEC-0049 Planned Lite and Pro Core

No built-in demo, test or default signing or licence key exists in a shipped build; test keys exist only inside tests

Depends on: SEC-0001

No default network binding

SEC-0050 Planned Lite and Pro Core

No listener is opened by default; any local server mode is off until the user turns it on and then binds to loopback only

Depends on: SEC-0001

No runtime CDN or remote asset loads

SEC-0051 Planned Lite and Pro Core

Fonts, scripts, images and data packs are bundled; nothing is fetched from a third-party host at run time

Depends on: SEC-0001

No founder or hidden auto-boot

SEC-0052 Planned Lite and Pro Core

No hidden start path, special account or auto-started service exists for the vendor or founder; every start path is documented and visible to the user

Depends on: SEC-0001

Offline guard enforces the no-hidden-doors rules

SEC-0053 Planned Lite and Pro Core

The offline guards in CI fail on sockets, URL literals, runtime CDN loads, default bindings, demo keys and auto-start code in the sources

Depends on: SEC-0001

Break-in tests per profile

SEC-0054 Planned Lite and Pro Core

For each tested profile there are tests that try to reach removed elements, tampered signatures, edited entitlements and expired grants, and must fail

Depends on: SEC-0001

Honest limit: code a person holds can be attacked

SEC-0055 Planned Lite and Pro Core

A determined local attacker can attack any code they hold; sensitive things therefore stay out of the build or on the company host, and this limit is recorded in the security model

Depends on: SEC-0001

Sensitive modules staged last

SEC-0056 Planned Lite and Pro Standard

In any rollout the ledger and customer-data modules are changed last, after the rest of the stage has proven itself

Depends on: SEC-0001