Participant device
Drafts and local private memory remain participant-controlled.
The map makes every trust boundary visible so that a short application-level claim cannot silently imply privacy across the web server, proxy, database, backup, operator, and legal-demand layers.
The participant device, WSGI application, MATM runtime, database, hosting proxy, and backup system are different trust domains. A request can be ephemeral in one layer and still appear in another unless every layer is configured and inspected. Concresca therefore keeps production privacy state NOT_OBSERVED until infrastructure evidence exists.
Drafts and local private memory remain participant-controlled.
No application request-body or raw-query logging.
Private content handling requires authenticated source and route reconciliation.
Migration stores policy and minimized receipts, not private query content.
Production log configuration remains unverified.
Must exclude ephemeral query data and honor deletion/expiry semantics.
NO JUDGMENT WHATSOEVER. Query, thought, identity, content, and participation are never converted into moral rank, character, intent, guilt, danger, trustworthiness, or standing.
Status: PARTIAL. Exact propositions are tracked in the claim ledger. Verification of one proposition does not verify an entire report or source family.
Private-query, identity separation, no-profile database, and anti-ratchet controls are current design requirements. They are not represented as deployed production infrastructure.
Local repository, browser, WSGI, and fixture evidence remains separate from MySQL, Passenger, public traffic, outside participation, Eviulon ratification, Patefacere adoption, or Evulgare certification.
Correction route. Challenge a claim through the claim ledger or the public clarification and correction route. One commissioned report family is never counted as independent corroboration.