Security and privacy
Staging discipline
Release rules from the security model: snapshots first, data never moves with code, a backup before any data-touching change, test on a copy, one stage per release, the previous build kept for real rollback, and ledger and customer data last. Parts exist as code (test on a copy, verified backup before removal); the rollout tooling does not.
Designed in a document, no code yet
What to plan for
- Rollout tooling not built
- Installer that leaves the data folder alone not proven
- Sensitive modules last
What the catalog lists
Planned items that match this topic (keyword match; read each as a pointer):
- Automatic local backup DATA-0001
- Point-in-time restore (snapshots) DATA-0017
- Sensitive modules staged last SEC-0056
- Automatic DB snapshot before risky ops FAIL-0011
Honesty note
Everything listed is a plan or a design principle. No app is released and nothing is audited or certified.