Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Security

The packaging security model

A short account of the eight rules in the repository's security model, what is built and tested, and what is not.

Status

Built (repo) Parts are tested library code; Designed the rest is designed. No external security review has been done, no real key exists, and this page is not a claim of any certification.

RuleIn plain wordsState
True removalA build holds nothing for elements you did not choose: no code, assets, database tables, menu entries or permissions. Hiding by a flag does not count. Built (repo) proved per profile by tests
Signed everythingPackages, update manifests, entitlements, the catalog and price documents are signed. A missing signature or empty checksum is an error, never a skip. Built (repo) test keys only
Local authority for offline use onlyA signed entitlement file per package is checked locally every time and decides offline use and nothing online. Built (repo)
Online features are decided by the hostOnline features need a short-lived signed grant (draft: at most 14 days). Editing the local app cannot create one. If a grant cannot be renewed the online feature pauses; selling and local data never depend on it. Built (repo) verification side only
No hidden doorsNo demo or default keys, no default network binding, no runtime CDN or remote asset loads, no founder or vendor accounts, no auto-start. Built (repo) source scans in four workspaces
Staging disciplineSnapshots first, data never moves with code, backup before any data change, test on a copy, one stage per release, previous build kept, ledger and customer data last. Designed partly coded
Break-in tests per profileTests attempt to forge, replay, swap and downgrade files for each profile. Built (repo)
An honest limitA person who holds the code can attack the code, so sensitive things stay out of the build or on the host. No claim

Not built

  • The company host (issuing grants, publishing revocations), device binding, and a launcher screen for entitlements.
  • The key ceremony and custody (D22) and the host design (D30).
  • Rollout tooling for "one stage per release", an installer proven to leave the data folder alone, and protection of the running interface.
  • An external security review and a full threat model.

Security themes · True removal · No hidden doors · Entitlement per package · What we ran