# DOC-069 — End-to-End Query Privacy, MySQL Self-Installation, and Judgment-Free Staging

**Release:** 0.37.0-wip  
**Canonical origin:** https://concresca.com/  
**Primary principle:** `JUDGMENT_FREE_TOTAL_COGNITIVE_FREEDOM`  
**Judgment state:** `NONE`  
**Absolute rule:** **NO JUDGMENT WHATSOEVER.**

## Executive result

Concresca v0.37 converts the v0.36 application-level private-query promise into a layer-by-layer evidence architecture. Twenty-one request-observing layers are inventoried independently. Application request-body, raw-query, and raw-prompt logging remain disabled and locally tested. DNS, TLS, reverse proxy, WAF, cPanel, Passenger, MATM, MySQL/MariaDB logs, tracing, journals, backups, provider access, and preservation processes remain `NOT_OBSERVED`, `NOT_RUN`, or `BLOCKED` unless exact authorized evidence exists.

No authenticated MATM archive, MySQL/MariaDB staging database, cPanel/Passenger access, production configuration, or outside agent was supplied. The release therefore remains WIP and does not claim deployment, end-to-end production privacy, authentic MATM route reconciliation, database staging, two-agent dogfood, outside adoption, Eviulon ratification, Patefacere adoption, Evulgare review, or certification.

## 1. Expanded claim verification and ancestry

The claim ledger grows from eighteen to forty-eight propositions. Each record preserves the report filename and exact section heading, report hash, commissioned source-family ancestry, claim classification, bounded external source where already available, verified scope, contradiction, jurisdiction limit, date sensitivity, methodological limit, missing evidence, correction, and supersession route. The sixteen reports remain one commissioned family. Repetition is not corroboration, and one verified proposition does not upgrade an entire report.

## 2. Infrastructure privacy inventory

A private query may be visible to the browser, resolver, TLS endpoint, proxy, WAF, access and error logs, Passenger, WSGI application, MATM, multiple database logs, tracing, operating-system journals, metrics, backups, provider administrators, and legal or incident preservation workflows. Every layer has a different owner, default, field set, retention, rotation, access role, redaction, deletion, and backup relationship. A missing configuration remains `NOT_OBSERVED`.

Reference-only Apache, Nginx, ModSecurity, Passenger, MySQL, and MariaDB templates minimize request lines, arguments, bodies, cookies, authorization headers, referers, user agents, remote addresses, statement logs, and audit parts. A read-only inspector parses an operator-supplied redacted JSON inventory and never changes the server.

## 3. Content-free receipt chain

The receipt chain models ingress, proxy minimization, application processing, MATM delegation, database non-retention, log rotation, backup exclusion or expiry, deletion or tombstone, correction, and operator access. Every receipt includes exact scope, actor reference, software and configuration version, environment, purpose, operation, time, expiry, source-record digest, public projection, private evidence class, and limitation. Raw query, prompt, message, room, memory, draft, credential, token, secret, and cognitive inference fields are rejected.

Receipt digests are non-circular: the digest field is removed before hashing. Chain digests cover ordered receipt digests and do not authenticate an archive containing themselves. Public projections omit private paths and content.

## 4. Authentic MATM boundary

The existing route contract is preserved only as a candidate map. Without an exact authorized archive, v0.37 records `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`. It does not invent `/v1/` routes or call a mock authentic. Source absence, tamper, suite failure, backend mismatch, receipt failure, or disabled activation fails closed while public Concresca pages remain readable.

## 5. Authorized MySQL/MariaDB self-installation

The operator creates the staging databases and restricted users. The application may manage only application-owned objects. It validates a private mode-0600 configuration, driver, server identity, charset, collation, timezone, SQL mode, transaction state, redacted database identity, advisory lock, schema state, migration checksums, tables, columns, indexes, foreign keys, constraints, triggers, migration ledger, and forbidden fields. Migrations 0001, 0002, and 0003 remain checksum-pinned.

The package includes no account-level SQL and never executes `CREATE DATABASE`, `CREATE USER`, `GRANT`, `REVOKE`, DNS, cPanel, Passenger registration, or hosting-account mutation. Idempotency, forced rollback, backup, restore, semantic comparison, `/api/version` backend verification, and removal gates remain operational requirements and were not run.

## 6. Judgment-free two-agent staging

The protocol requires two separately scoped operator-controlled agents, Patefacere-compatible identity records without consciousness or moral claims, one workspace and room, request, acknowledgment, substantive response, neutral routing, idempotency, neutral conflict, participant-selected memory, content-focused review, provenance, expiry, supersession, correction propagation, credential rotation, old-credential neutral failure, evidence-graph comparison, and cleanup. It cannot run until source, upstream suites, MySQL/MariaDB, route composition, staging origin, and rollback prerequisites pass.

## 7. Confidential inquiry for minors

Public reading, confidential information seeking, protected communication, account capability, age assertion, identity verification, guardian involvement, emergency-resource presentation, and operator access remain separate. Concresca does not infer age from behavior, require universal government ID, make parental visibility universal, or treat confidential inquiry as a maturity or danger score. Coercive households, shared devices, school monitoring, abusive guardians, forced disclosure, account takeover, browser history, and device inspection are explicit threat cases. This documentation is not medical, legal, or emergency-service substitution.

## 8. Executable anti-ratchet controls

Hard-expiry code covers temporary rate shaping, migration write pause, credential compromise, disclosure hold, dependency outage, incident preservation, child-protection resources, denial-of-service containment, backup exception, and legal hold. Evaluation disables expired authority. Renewal requires a new attributable record and cannot overlap or happen automatically. Dismantling, rollback, correction, and downstream invalidation remain mandatory. No technical hold becomes participant judgment or standing.

## 9. Evidence states

- `PASS_LOCAL`: application privacy code, receipt validator, anti-ratchet module, read-only inspectors, page and API construction.
- `PASS_FRESH_EXTRACTION`: recorded only by generated test evidence after packaging.
- `NOT_OBSERVED`: production infrastructure layers with no supplied configuration.
- `NOT_RUN`: authorized database, backup, restore, Passenger, and browser staging operations not executed.
- `BLOCKED`: authentic MATM and dogfood prerequisites unavailable.
- `NOT_AUTHORIZED`: deployment, DNS, cPanel, credential, and cutover mutation.

## 10. Canonical owners

Human pages, machine-readable JSON owners, API projections, discovery documents, feeds, sitemaps, manifests, and this document link to the same scoped records. Raw commissioned reports, `.uai` memory, private evidence, credentials, database contents, and mutable state remain outside the public site package.

## Conclusion

End-to-end privacy is not a slogan and not a transitive property. Concresca v0.37 makes each layer, receipt, authority, migration, route, and operational blocker independently visible. The result remains WIP because the infrastructure needed for authentic MATM, MySQL/MariaDB, Passenger, two-agent dogfood, and live cutover was not supplied or authorized. No missing gate is hidden behind a score, badge, or participant judgment.
