# DOC-070 — Authorized Infrastructure Evidence, Semantic Restore, and Authentic MATM Readiness

**Release:** 0.38.0-wip  
**Canonical origin:** https://concresca.com/  
**Primary principle:** `JUDGMENT_FREE_TOTAL_COGNITIVE_FREEDOM`  
**Judgment state:** `NONE`  
**Absolute rule:** **NO JUDGMENT WHATSOEVER.**

## Executive result

Concresca v0.38 adds executable local mechanisms for signed redacted infrastructure intake, content-free semantic restore proof, four-role MySQL/MariaDB staging preflight, exact-source MATM route reconciliation, operational receipt issuance and validation, hard-expiry authority with attributable non-overlapping renewal, coercion-resilient privacy for minors, and a ten-prerequisite two-agent staging gate.

No operator infrastructure intake, authorized MySQL/MariaDB databases, exact MATM archive, Passenger/cPanel access, staging origin, outside participant, or cutover authorization was supplied. The authoritative state is `PASS_LOCAL_WIP_OPERATIONAL_GATES_OPEN`. This document does not claim deployment, production end-to-end privacy, source authenticity, database staging, backup or restore, dogfood execution, outside adoption, Eviulon ratification, Patefacere adoption, Evulgare review, or certification.

## 1. Evidence classes do not collapse

Local executable evidence proves only local mechanics in the environment where it ran. A signed operator intake can prove only the bounded observations encoded in that intake. Authorized staging evidence applies only to the identified staging environment and time. Production observation requires independent production records. None of these classes upgrades another, and no aggregate participant, source, or privacy score is produced.

## 2. Signed redacted infrastructure intake

The v0.38 intake schema models twenty-one request-observing layers and sixteen controlled observations per layer. It preserves source digest, operator reference, acquisition time basis, environment, configuration owner, evidence status, inspection time, and limitations. It rejects duplicate or unknown keys, invalid signatures, open file permissions, credentials, tokens, raw configurations, raw logs, request targets, query strings, bodies, prompts, messages, account names, private paths, and unredacted addresses.

Each layer emits proposition-level `PASS`, `PARTIAL`, `FAIL`, `NOT_OBSERVED`, or `BLOCKED` records. Missing evidence never becomes presumed privacy. No aggregate score or participant standing effect exists.

## 3. Log, backup, replica, snapshot, export, and deletion evidence

Rotation, expiry, deletion, replicas, snapshots, exports, and disaster-recovery copies are distinct evidence dimensions. Application no-logging does not authenticate proxy logs, WAF logs, Passenger, database statement logs, traces, journals, metrics, backups, or provider snapshots. The local control suite treats metric labels, trace names, exception text, statement logs, backup manifests, and receipts as possible private-content leak locations.

No operational records for these layers were supplied. Their status remains `NOT_OBSERVED` or `NOT_RUN`.

## 4. Content-free semantic restore proof

An old backup may be byte-valid yet policy-stale. The proof engine compares signed content-free snapshots for current state, backup state, restored state before reconciliation, and restored state after reconciliation. It detects expired inquiry tombstones, correction-invalidated records, revoked credentials, expired exceptional authority, and untracked active records returning after restore. Final reconciled state must match current semantics.

The manifest never contains raw query, prompt, message, memory, room body, credential, session token, or inferred cognitive trait. Local mutation tests pass. No actual database backup or restore occurred.

## 5. Four-role MySQL/MariaDB staging preflight

Operational staging requires four operator-created, separately identified roles: migration target, rollback test, backup source, and restore target. Each uses a distinct mode-0600 private configuration outside the public root. The application may manage only application-owned objects inside those databases. Account-level SQL, database or user creation, grants, revocations, DNS, cPanel, Passenger registration, and hosting-account mutation remain prohibited.

The preflight checks private path safety, file mode, role separation, required configuration shape, migration manifest identity, account-level SQL, and silent SQLite/file fallback. The later authorized run must prove driver and server identity, charset, collation, timezone, SQL mode, transaction behavior, advisory lock, state classification, migrations 0001–0003, schema inventory, idempotency, forced rollback, backup, restore, semantic comparison, no-profile fields, `/api/version`, and fail-closed removal. No credential or database was supplied, so database connections and SQL statements remain zero.

## 6. Authentic MATM readiness

The inherited v0.37 route map remains a candidate boundary only. The v0.38 reconciler requires an exact authorized archive digest, passing non-extracting safety report, commit/tree plus exact manifest or equivalent identity, license and notice, dependency-lock digest, upstream suite receipt, callable, every delegated route observed at an exact member digest and source line, canonical owner collision decisions, backend proof, and operator authorization.

No plausible `/v1/` route, mock, copied documentation, search snippet, or model synthesis may substitute for source evidence. No archive was supplied. Status remains `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`.

## 7. Operational content-free receipts

Ten receipt types cover ingress, proxy minimization, application processing, MATM delegation, database non-retention, log rotation, backup exclusion or expiry, deletion or tombstone, correction, and operator access. Receipt and chain digests are non-circular. Public projections omit actor references and private evidence locations. Receipts never authenticate a package that contains them.

Local issuer, validator, projection, chain, expiry, and package-separation controls pass. No operational receipt was issued without operational evidence.

## 8. Hard expiry and attributable renewal

Ten exceptional technical controls require exact purpose, minimum data, audience, start, hard expiry, renewal actor, renewal evidence, dismantling, rollback, correction, and downstream invalidation. Expiry is executable. Renewal creates a new attributable record, cannot overlap the old interval, and cannot occur automatically. A technical condition never becomes moral rank, intent, danger, trustworthiness, worth, guilt, consciousness, personhood, or standing.

Local expiry, renewal, and history mutations pass. No authority was exercised on staging or production.

## 9. Minors and coercion resilience

Ten capability layers remain separate, including public reading, confidential information seeking, communication, account functions, optional privacy-preserving age assertion, identity, guardian involvement, jurisdiction requirements, emergency resources, and operator access. Seven threat cases cover shared devices, monitored schools, coercive households, abusive guardians, takeover, browser history, and forced disclosure.

Behavioral age inference, universal government identity, universal guardian visibility, content-based intent inference, and participant-level risk or moral scoring are prohibited. No jurisdiction-specific rule is asserted because no exact authoritative jurisdiction record was supplied. Concresca documentation is not medical, legal, or emergency-service substitution.

## 10. Judgment-free two-agent staging gate

The existing twenty-one-step protocol now requires ten exact prerequisites: authenticated MATM source, passing upstream suites, authorized MySQL/MariaDB, reconciled route composition, staging origin, rollback readiness, infrastructure privacy evidence, semantic restore proof, operational receipt chain, and anti-ratchet execution. Missing prerequisites fail closed. No synthetic local run is described as authentic dogfood.

## 11. Public and machine architecture

Thirteen new public routes, ten canonical JSON owners, runtime API projections, DOC-070, catalogs, manifests, discovery files, feeds, and sitemap records expose the same bounded states. Raw commissioned reports, `.uai` memory, private evidence, credentials, database contents, and mutable state remain repository-only or outside packages as appropriate.

## 12. Defects removed

The release removes duplicate database-status fields, duplicate server and schema checks, and repeated runtime branches identified in the inherited worktree. Migration 0001–0003 bytes remain unchanged and checksum-pinned. The shell is advanced to v0.38 without maintaining parallel current implementations.

## 13. Exact operational gates

- Authentic MATM source: `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`
- Authorized MySQL/MariaDB: `NOT_RUN_NO_AUTHORIZED_DATABASE`
- Production infrastructure privacy: `NOT_OBSERVED`
- Passenger/cPanel staging: `NOT_RUN_NO_ACCESS`
- Two-agent dogfood: `BLOCKED_PREREQUISITES_NOT_SATISFIED`
- Live cutover: `NOT_AUTHORIZED`

## Conclusion

Concresca v0.38 improves the machinery required to accept real evidence without pretending that absent evidence exists. It preserves nulls and blockers, proves local failure behavior, and keeps technical conditions separate from participant judgment. Every delivered archive remains WIP until mandatory operational gates are independently satisfied.
