Security
The packaging security model
A short account of the eight rules in the repository's security model, what is built and tested, and what is not.
Status
Built (repo) Parts are tested library code; Designed the rest is designed. No external security review has been done, no real key exists, and this page is not a claim of any certification.
| Rule | In plain words | State |
|---|---|---|
| True removal | A build holds nothing for elements you did not choose: no code, assets, database tables, menu entries or permissions. Hiding by a flag does not count. | Built (repo) proved per profile by tests |
| Signed everything | Packages, update manifests, entitlements, the catalog and price documents are signed. A missing signature or empty checksum is an error, never a skip. | Built (repo) test keys only |
| Local authority for offline use only | A signed entitlement file per package is checked locally every time and decides offline use and nothing online. | Built (repo) |
| Online features are decided by the host | Online features need a short-lived signed grant (draft: at most 14 days). Editing the local app cannot create one. If a grant cannot be renewed the online feature pauses; selling and local data never depend on it. | Built (repo) verification side only |
| No hidden doors | No demo or default keys, no default network binding, no runtime CDN or remote asset loads, no founder or vendor accounts, no auto-start. | Built (repo) source scans in four workspaces |
| Staging discipline | Snapshots first, data never moves with code, backup before any data change, test on a copy, one stage per release, previous build kept, ledger and customer data last. | Designed partly coded |
| Break-in tests per profile | Tests attempt to forge, replay, swap and downgrade files for each profile. | Built (repo) |
| An honest limit | A person who holds the code can attack the code, so sensitive things stay out of the build or on the host. | No claim |
Not built
- The company host (issuing grants, publishing revocations), device binding, and a launcher screen for entitlements.
- The key ceremony and custody (D22) and the host design (D30).
- Rollout tooling for "one stage per release", an installer proven to leave the data folder alone, and protection of the running interface.
- An external security review and a full threat model.
Security themes · True removal · No hidden doors · Entitlement per package · What we ran