True removal: a build holds nothing for elements outside its spec
SEC-0042 ○ Planned Lite and Pro CoreA package contains no code, assets, migrations or data for elements that are not in its spec or entitlement; the closure of the spec is the whole build
Depends on: SEC-0001
Hiding by flag does not count as removal
SEC-0043 ○ Planned Lite and Pro CoreA feature switched off by a setting or flag but still shipped is treated as present; only absence from the build counts
Depends on: SEC-0001
Absence test per profile: files
SEC-0044 ○ Planned Lite and Pro CoreFor each tested profile the engine checks that files of elements outside the closure are not in the package
Depends on: SEC-0001
Absence test per profile: commands and menus refuse
SEC-0045 ○ Planned Lite and Pro CoreFor each tested profile every operation of an element outside the enabled set is refused and no menu entry exists for it
Depends on: SEC-0001
Absence test per profile: database schema lacks removed tables
SEC-0046 ○ Planned Lite and Pro CoreFor each tested profile a database created by the build contains no tables of elements outside the closure
Depends on: SEC-0001
Signed everything: builds, updates, entitlements, catalog and price documents
SEC-0047 ○ Planned Lite and Pro CoreEvery artifact that changes what the app does or what it may do is signed with Ed25519 and verified before use
Depends on: SEC-0001
Signature is mandatory, no skip path
SEC-0048 ○ Planned Lite and Pro CoreA missing, empty or malformed hash or signature is an error, never a reason to skip verification
Depends on: SEC-0001
No demo or default keys in any build
SEC-0049 ○ Planned Lite and Pro CoreNo built-in demo, test or default signing or licence key exists in a shipped build; test keys exist only inside tests
Depends on: SEC-0001
No default network binding
SEC-0050 ○ Planned Lite and Pro CoreNo listener is opened by default; any local server mode is off until the user turns it on and then binds to loopback only
Depends on: SEC-0001
No runtime CDN or remote asset loads
SEC-0051 ○ Planned Lite and Pro CoreFonts, scripts, images and data packs are bundled; nothing is fetched from a third-party host at run time
Depends on: SEC-0001
No founder or hidden auto-boot
SEC-0052 ○ Planned Lite and Pro CoreNo hidden start path, special account or auto-started service exists for the vendor or founder; every start path is documented and visible to the user
Depends on: SEC-0001
Offline guard enforces the no-hidden-doors rules
SEC-0053 ○ Planned Lite and Pro CoreThe offline guards in CI fail on sockets, URL literals, runtime CDN loads, default bindings, demo keys and auto-start code in the sources
Depends on: SEC-0001
Break-in tests per profile
SEC-0054 ○ Planned Lite and Pro CoreFor each tested profile there are tests that try to reach removed elements, tampered signatures, edited entitlements and expired grants, and must fail
Depends on: SEC-0001
Honest limit: code a person holds can be attacked
SEC-0055 ○ Planned Lite and Pro CoreA determined local attacker can attack any code they hold; sensitive things therefore stay out of the build or on the company host, and this limit is recorded in the security model
Depends on: SEC-0001
Sensitive modules staged last
SEC-0056 ○ Planned Lite and Pro StandardIn any rollout the ledger and customer-data modules are changed last, after the rest of the stage has proven itself
Depends on: SEC-0001