Security and privacy
Removal audit chain
Each removal decision is written to a local log in which every entry commits to the previous one, and the current state is cross-checked against the chain. It is tamper-evident, not tamper-proof; publishing the head hash outside the computer (for example in a printed or exported record) is a planned mitigation.
Built in the repository (checked files or tested library code; not a product you can run yet)
What to plan for
- Someone who recomputes the whole chain can rewrite history
- No trusted time offline
- Local only
What the catalog lists
Planned items that match this topic (keyword match; read each as a pointer):
- Removal log DATA-0045
- Audit log tamper evidence SEC-0002
Honesty note
Everything listed is a plan or a design principle. No app is released and nothing is audited or certified.