confidence / 4.0.0 Beta 2

Production Readiness Hardening

Applies the highest-priority independent-assessment remediations to request identity, bounded ingestion, scan lifecycle, sessions, consent and encrypted recovery exports.

Status
archived
Published
2026-08-20
Modified
2026-08-20
Category
confidence

Included changes

  1. 01Production rate limiting now fails each unattributed request closed and requires exactly one verified proxy identity source, while public routes use separate buckets.
  2. 02Scraper decompression, public AI bodies, policy context and model output are bounded; full scans use a durable lease, renewal and stale-run recovery.
  3. 03Admin sessions have a dedicated revocation version, subscriber alerts require a 48-hour double opt-in, and encrypted exports cover all 31 application tables in a versioned envelope.

Interpretation boundaries

  • 01The candidate still requires Hostinger staging with the real proxy header, 16/16 migrations, SMTP confirmation and post-deploy smoke evidence.
  • 02Backup-file verification is not a restore drill; PostgreSQL, object storage and canonical reads remain separately gated.

Evidence links