Protect the host
One persistent Linux instance; HTTPS origin, owned domain, private runtime secrets and no publicly served source directories.
A release checklist for the actual host: identities, storage, email, restore, monitoring and customer acceptance.
No hosting, native platform, mail provider, payment provider or signature provider is activated by installing this source package. This is the handoff checklist for your later connections.
One persistent Linux instance; HTTPS origin, owned domain, private runtime secrets and no publicly served source directories.
Register, verify email, enroll MFA, create a project, run or submit a job, review a quote, receive the authorized release and open a support request.
Wrong tenant, expired grant, modified artifact, native timeout, cancellation, outbox exhaustion and revoked signing key must fail safely.
Stop workers, create an encrypted snapshot, verify its manifest and restore to an empty host. Preserve both MFA and evidence signing identities.
Probe the hosted origin independently; alert on failure, disk pressure, queue delay and dead-letter mail. A status page is not an external observer.
Run the supplied networked browser and load checks. Review screen readers, mobile devices, contrast, zoom and keyboard authentication. Do not infer certifications from automated test counts.