v0.2.0 (alpha) is shipped and public. The evidence spine, encryption, offline-first
sync, bilingual app with automated accessibility coverage, export packets, and optional
relay are implemented and tested (see CHANGELOG.md). This document is the path from a working
reference implementation to something a tenant union can rely on — and an honest
account of what is deliberately left undone.
It is a working document, not a promise. Dates are horizons for a small volunteer
effort and will move; the ordering and the exit criteria matter more than the
calendar. Decisions of consequence are recorded as ADRs in docs/adr/.
Execution snapshot (2026-07-22). The dated roadmap-drain register reconciles every open item against current-main code/tests and the live GitHub queue. No agent-executable feature issue remains open. The work still listed below is either an explicit protocol/research gate or an external outcome that requires reviewers, partners, maintainers, hardware, funding, or distribution credentials. The next bounded opportunity portfolio is in the novel-use-case implementation plan.
Implementation update (2026-07-23). The shared profile, artifact, relationship, handoff, local-pattern, and partner-capsule primitives from that plan are implemented as case schema v3 / packet v4 and exposed through the CLI and localhost app. The profiles that depend on legal, medical, inspector, accessibility, housing-authority, or adopter review remain explicitly
external_review_required; those human gates are not treated as completed.
Roadmap reconciliation (2026-08-22). This file,
docs/novel-use-cases-plan.md(the product-expansion portfolio), and the gitignored, maintainer-localdocs/productionization.md(the v1.0-gate task tracker; deliberately not committed, per the alpha-caveat and audit-recruitment discipline in workstream A/D) previously drifted: the trust-gate horizon (this file) never named the product-expansion workstream at all, and the use-case plan's own execution narrative had gone stale relative to its own status line. Workstream E below folds product expansion into the same multiyear picture as the trust gate instead of leaving it a separately-tracked, unlinked document; see workstream E for what that reconciliation found and fixed.
Alpha caveat. Until the v1.0 gate below is met, do not rely on habitable for real legal matters. See Honest limits in the README.
- Vision & north star
- Guiding principles
- Releases & versioning
- The v1.0 gate (when "alpha" comes off)
- Release horizons
- Workstreams
- Risks & mitigations
- Measuring progress without surveillance
- Non-goals
- How this roadmap is maintained
A tenant — or their union — can document a habitability problem on the only device they have, offline, and later hand a court or inspector a packet that the other side can verify hasn't been altered, without anyone but the keyholders ever being able to read the tenant's data, and without trusting this project to do so. The north-star metric is not downloads; it is: a tenant won, or was protected, partly because the record held up — and nothing leaked in the process.
These are invariants. No item on this roadmap may violate them; an item that requires violating one is the wrong item.
- No server-side personal data, ever. No cloud of cases, no accounts, nothing to subpoena from the project.
- No telemetry, no analytics. The tool measures nothing about its users (this constrains how we measure our own progress — see below, and we accept that).
- No central authority over a union's records. Forking or self-hosting changes nothing about who can read the data: only the keyholders.
- Tamper-evidence is mandatory. The verifier must never accept altered evidence as intact, and must never reject sound evidence.
- The adversary is a retaliating landlord with resources and motive. Defaults assume that.
- Say what it does not do. Honesty about limits is a feature; overclaiming in a courtroom fails the people relying on the tool.
- Accessibility and bilingual reach are not optional. A tool a disabled or Spanish-speaking tenant cannot operate has failed at its purpose.
- SemVer for the package. The packet format and the verification protocol are versioned independently, and the contract is: old packets keep verifying. A change that could break verification of an existing packet is a protocol major bump with a migration note, never a silent change.
- A release is tagged, has a
CHANGELOG.mdentry, and passes the full gate (make verify- the
a11ybrowser gate + CodeQL). Actions are SHA-pinned and dependencies locked; release artifacts carry a build provenance attestation and an SBOM since v0.2.0 (see.github/workflows/release.yml). Signed release tags are now enforced by the active protected-tag ruleset and the release workflow's signature, version, and reviewed-mainline guards (see workstream A). Provenance attestation proves how an artifact was built; the signed tag separately binds the maintainer-approved release identity.
- the
v1.0 is not a feature count; it is a trust threshold. All of the following must be true and documented before the "alpha — do not rely on this" caveat is removed:
- An independent security review and cryptographic review completed, with findings remediated or formally accepted (workstream A).
- A recorded human screen-reader pass (NVDA + VoiceOver) at WCAG 2.2 AA with no open moderate-or-worse finding (workstream B).
- At least one real tenant-union or legal-aid pilot completed, with written outcomes — including whether a produced packet was usable in its intended forum (workstream D).
- The threat model independently reviewed and its residual risks re-confirmed (workstream D), including a lawyer's read of the "not legal advice / no admissibility guarantee" framing.
- Signed release tags + build provenance in place (workstream A). Build
provenance attestation and an SBOM ship since v0.2.0; the active
v*ruleset requires signed tags and the release job rejects an unsigned, version-mismatched, off-mainline, or wrong-commit tag. - Recovery, key-rotation, and multi-device flows documented and tested for a non-technical organizer (workstream C).
Until every box is checked, the project stays pre-1.0 and the caveat stays.
Targets for a small volunteer/solo effort, updated after v0.4.0 (2026-08-16). Expect slip.
| Release | Horizon | Theme | Headline goals | Product expansion (workstream E) |
|---|---|---|---|---|
| v0.1.x | shipped | Initial alpha | Evidence core, local vault, verifier, sync, and app baseline | — |
| v0.2 | shipped June 2026 | Assurance groundwork | Verifier fuzzing; archive/re-timestamping; provenance; security/reviewer handoff materials | — |
| v0.3.0 | shipped 2026-07-23 (CHANGELOG-recorded; folded into the v0.4.0 tag below rather than tagged on its own) | Use-case foundation | Roadmap drain / novel-use-cases plan; bounded public review hub | N0–N4 primitives and all ten use-case profiles shipped (§E) |
| v0.4.0 | shipped & tagged 2026-08-16 | Packet-seal & release hygiene | Whole-packet RFC 3161 seal (ADR 0011); --expected-producer-key; uv sync --locked lockfile gate |
Consent-record withdrawal semantics for local aggregation (N4) |
| Unreleased | now (2026-08-22) | — | — | Profile review-expiry enforcement (ADR 0012): selection refuses an expired profile, export falls back and discloses rather than presenting stale guidance |
| v0.5 (beta) | mid/late 2027 | Pilot-ready | Security/crypto audit underway; recorded AT pass; 1–2 union/legal-aid pilots running; multi-device + recovery UX; one-click desktop packaging (the native-mobile spike is already done — see workstream C — and blocked on upstream cryptography mobile wheels, not on this) |
Solo-buildable Now items from Beyond the current portfolio: move-out/deposit-dispute record, jurisdiction template growth; named reviewer/partner secured for at least one of the six external_review_required profiles; joint multi-tenant case bundle prototyped |
| v1.0 | ~2028 | Trustworthy | The v1.0 gate met; "alpha" caveat removed | At least one external_review_required profile promoted to maintainer_reviewed on a recorded review |
| v2.x+ | beyond | Reach & resilience | More languages/jurisdictions; metadata-resistant sync; broader interop; shared governance | Remaining partner-gated profiles as partners arrive; protected-activity timeline only after its framing ADR; jurisdiction/language growth using the now-enforced expiry mechanism |
Each item lists an objective and, where useful, an exit criterion / trigger. Items
marked shipped are on current main and listed only for context.
Packet-integrity claims live here; this work gets the most scrutiny.
- Shipped: SHA-256 fixity, RFC 3161 timestamps (local issuer + HTTP client + offline dev
TSA), hash-linked custody with salted actor commitments, the standalone verifier,
SHA-pinned CI, CodeQL,
pip-audit, Dependabot. - Shipped (FIX-10): No wall-clock/node metadata in exported identifiers. Every id in a
packet (issue, capture, timeline entry, custody item) and the exported
hlcfields are now opaque, per-case-salted digests that encode neither the device wall clock nor the HLC node id; the hybrid logical clock stays internal for CRDT ordering/merge. Bundle format bumped topacket_version2 (v1 packets still verify, guarded by the golden corpus); atest_guardsinvariant asserts no exported field reveals the wall-clock ms or node id. - Shipped: Continuous real public-TSA integration. Objective: prove tokens from real
authorities (e.g. FreeTSA, DigiCert) verify end to end, not just the local issuer.
The scheduled, network-gated
tsa-integrationworkflow stamps and verifies against FreeTSA and DigiCert; its first three weekly runs are green. - Shipped: Archive / re-timestamping. Objective: keep old packets verifiable after a TSA
signing cert expires. Exit:
habitablecan re-timestamp an existing token and the verifier accepts the archive chain; covered by a test with an expired-cert fixture. - Shipped (R-16): Multiple-authority redundancy by default. Objective: no packet's proof rests on a single TSA. Both the online capture path and deferred-capture resolution stamp against N configured authorities (best-effort extras that never block), and the verifier reports per-authority status.
- Shipped (in-repo): Property-harden the verifier — and the primitives under it.
The Hypothesis hostile-input target runs in every merge gate with no accept-on-tamper
and no crash. The four primitives the verifier's verdicts rest on — canonical JSON,
the hash-linked custody chain, sealed-box/vault AEAD, and timestamp-token
parse/verify — now carry their own property suites
(
tests/test_property_invariants.py, the primitive-level targets named in the local productionization plan’s §E17): hostile input yields exactly one named error, no custody reordering/replay/interior deletion/field edit is accepted, and — exercised both with a synthetic certificate anchor configured and with none — no token mutation can move an attestedgen_time/digestor manufacture a trusted chain. Three limits are pinned executably rather than claimed away: the chain proves a prefix (suffix truncation is caught by the separately committed head hash, not by the chain); an RFC 3161 CMS wrapper legitimately carries bytes outside its signature; and an anchoredtrusted_chainis losable — editing the embedded certificate breaks the anchor match, the fail-closed direction. §E17's stateful harness over hostile packet/token input is still open, as is OSS-Fuzz integration — a separate ecosystem/discoverability improvement, not missing in-repo adversarial coverage. - Shipped: Signed releases + build provenance (SLSA). Tagged releases must
resolve to reviewed
mainhistory, carry an allowed SSH signature, match the package version, and publish the exact reproducibility-checked artifacts with SBOM and Sigstore provenance. The active protected-tag ruleset preventsv*tag update/deletion and requires signatures; seedocs/releasing.md. - Shipped: Reproducible wheel and relay-image builds. Objective: the same source yields
the same artifacts.
make repro/scripts/check_reproducible_build.pybuilds the wheel and sdist twice from independent clean source copies with a normalizedSOURCE_DATE_EPOCH/PYTHONHASHSEEDand fails on any byte difference; thereleaseworkflow runs it as a release-blocking gate.make relay-reproindependently builds two no-cache linux/amd64 OCI relay archives with the pinned base and fixed source epoch, rewrites layer timestamps, and fails unless the complete archives are byte-identical; it runs in both the container merge gate and release workflow. Seedocs/releasing.md. - Versioned scoped/rehashed custody views (P0 restoration). Objective: restore issue/date-scoped packets and issue-subset organizer shares without exposing identifiers from records outside the declared scope. Current safety state: packet-v3 and sync-v2 scoped operations fail before any output or message is published; whole-unit/full-case operations remain available. Exit: new packet and sync protocol versions define a derived custody-view schema that binds the selected scope and entries, rehashes the view under its own domain and labels, preserves a verifiable relationship to the source proof where possible, and never deletes arbitrary links or presents a truncated source chain as complete. Golden compatibility, adversarial privacy tests, atomic-publication tests, migration notes, and independent crypto review are required before re-enabling the CLI/app selectors.
- Independent security & cryptographic review. Objective: an outside expert audits
the crypto (vault, sealed-box sync, custody commitments) and the verifier. Trigger:
before v0.5/beta and a precondition of v1.0; findings remediated or formally accepted in
docs/audits/.
- Shipped: WCAG-targeted bilingual (EN/ES) app gated by axe-core (EN+ES, zero
violations) plus structural, keyboard-navigation, and 320px-reflow tests; an
axe-tested
packet.html; a PDF with language + DisplayDocTitle + outline; and a documented manual-testing protocol. These are automated/mechanical results, not a human conformance finding. - Shipped (FIX-12): Real pluralization and locale formatting. CLDR cardinal plural
rules for EN/ES in both CLI and web app; ICU-MessageFormat subset (
{name}placeholders and{name, plural, ...}) for plural-aware strings; locale-aware number/date/datetime formatting;scripts/check_i18n_parity.pyenforces plural-category and placeholder parity across locales; 65 comprehensive tests covering all plural categories and formatting functions. - Recorded human screen-reader pass. Objective: confirm the app is usable with AT,
which automation can't certify. Exit: a dated NVDA + VoiceOver pass per
docs/accessibility/manual-testing.mdrecorded indocs/audits/, no open moderate+ finding; repeated each release (gate item for v1.0). - Fully tagged PDF/UA packet remains unshipped. ADR 0004 designates
packet.htmlas the accessible rendering and the current PDF as a print convenience because reportlab's open-source API has no marked-content. Revisit PDF/UA only if a viable open-source tagging path appears; do not claim the current PDF is tagged. - Languages beyond EN/ES. Objective: serve more communities. Exit: a documented localization-contributor process and ≥1 added language with string parity enforced (the i18n parity test already guards this).
- Shipped (R-41/R-04): Plain-language & cognitive review. A reviewed plain-language
pass (target ~grade 6–8) over the in-app EN/ES copy (
app/i18n/) and the setup guide: jargon such as "Device fingerprint," "Chain of custody," "Awaiting timestamp," and "Content hash" replaced or glossed with in-context help; the Spanish de-lawyered and its timestamp term (sello de tiempo) partially made consistent. Honest-limits strings were kept at full strength and key parity held (tests/test_app_i18n.py,scripts/check_i18n_parity.py). The dated review record — target, method, every term changed, and what remains for a native-speaker / stressed-user pass — is atdocs/audits/plain-language-review.md. The final action-firstresolve_*/Spanish timestamp-term cleanup and guard shipped in the 2026-07-22 roadmap drain. Remaining (documented there): a native-speaker ES review, a measured readability score, and a cognitive walk-through. - Shipped: Low-end-device performance budget. A documented latency budget for the
local path — per-operation targets for content hashing, seal/store, custody append,
CRDT merge, and packet assembly — tied to a reference low-end device modeled as ~10×
slower than the CI runner, with network TSA latency explicitly excluded (it is
deferred, off the capture path).
tests/test_perf_budget.pyasserts the budget on every CI run (make test), anddocs/performance-budget.mdrecords the model and the tolerance band. Remaining: replace the 10× model with a measurement on named reference hardware once mobile packaging lands (see workstream C).
- Shipped: CLI; loopback app server; installable PWA shell assets (manifest, maskable/Apple icons, offline service worker) for same-device desktop evaluation; offline-first CRDT sync over a shared directory or the optional ciphertext-only relay; minimal jurisdiction packet templates.
- Native mobile packaging. Objective: a home-screen app that carries the engine
on-device (it's local-first — not a wrapper around a hosted site). Exit: a spike with
BeeWare/Briefcase or Tauri embedding the loopback API the PWA already speaks; then a
documented build. Note: signed App Store / Play Store binaries need platform accounts
and keys and may remain out of scope. The PWA shell can install in supported desktop
browsers, but it is not a supported phone path because the Python engine is not on-device.
Spike done (2026-07-09): see
docs/research/native-mobile-packaging-spike.md— the current Tauri community-plugin path is unsuitable (its mobile RustPython runtime cannot loadcryptography/pillow); the spike reports an end-to-end Briefcase hello-world Android build, but no APK or reproducible build recipe is committed. Packaging habitable has no off-the-shelf path until currentcryptographymobile wheels exist or the project takes on a reviewed cross-build. The product build remains not shipped; this closes only the research spike. - Desktop packaging. Objective: a one-click desktop app for organizers. Exit: a packaged build (e.g. Briefcase/Tauri) that launches the app with no terminal.
- Partial: Multi-device & key lifecycle UX. Authenticated case-bound pairing, passphrase hardening, DEK rotation, recovery blobs, M-of-N social recovery, CLI round trips, and organizer documentation ship. Remaining exit: non-technical organizers complete add-device, backup, rotate, lose-device, and restore drills; recovery limits remain clearly communicated.
- Partial: Merge/conflict surfacing. Authenticated per-field provenance and a CLI view identify the winning current value's device and time. A complete edit/conflict history is not shipped because the state-based CRDT does not retain overwritten values; it needs a versioned append-only change-log design and organizer validation before an app review view can claim completeness.
- Shipped, opt-in: Metadata-resistant sync (relay).
PaddingTransportbuckets sizes and posts fixed real-plus-decoy batches, hiding exact size and real-message count within a batch. The threat model and observability matrix disclose residual timing, IP, room-activity, and cross-sender-mixing exposure; those cannot be described as hidden. - Jurisdiction template library. Objective: packets that match local expectations without touching the verification protocol. Exit: a community-contributable set of presentation-only templates (the config surface exists; this grows it).
- Shipped baseline: Data portability / interop. The versioned JSON Schema, embedding cookbook, Apache-licensed evidence kernel and golden corpus, strict BagIt transfer adapter, and signed-receipt reference importer document and test portable handoff. A production case-management connector remains adopter-owned, not an implied integration.
- Tenant-union & legal-aid pilots. Objective: validate the tool in the real power-imbalance it's built for. Exit: ≥1 pilot with written outcomes, including whether a packet was usable in its forum and what broke (gate item for v1.0).
- Contributor growth & onboarding. Objective: lower the bus-factor. Exit: a "good
first issue" set, an onboarding path beyond
CONTRIBUTING.md, and ≥1 sustained outside contributor. Shipped (R-42/R-43 tooling): the good-first-issue set, the newcomer architecture walkthrough (docs/good-first-issues.md), and a one-command onboarding path —./scripts/bootstrap.shplus a devcontainer/Codespace config (.devcontainer/) that provisions the full Python 3.14 + uv environment. The remaining exit criterion — ≥1 sustained outside contributor — is a social outcome, not a tooling gap, and stays open. - Shared governance. Objective: move from benevolent-maintainer toward shared
stewardship as contributors arrive. Trigger: sustained contributors → adopt a documented
decision process and
MAINTAINERS/GOVERNANCEevolution indocs/governance.md. - Sustainability without strings. Objective: keep the project running with no paid infrastructure and no vendor lock-in. Exit: a funding approach (grants/mutual-aid) that never introduces a server holding tenant data or a dependency on a single vendor.
- Threat-model evolution. Objective: keep the adversary model current. Exit: a
scheduled re-review of
docs/threat-model.mdeach release with sign-off. - Disclosure maturity. Objective: a trustworthy security front door. Exit: a tested coordinated-disclosure flow and published advisories where relevant.
- Education. Objective: organizers can self-serve. Exit: the "set up your union in an afternoon" guide kept current; short task walkthroughs.
New user-facing capability — as opposed to workstreams A–D, which build the
trust a tenant needs to rely on what already exists. Detailed scoring,
acceptance criteria, and delivery plans live in
docs/novel-use-cases-plan.md; this section
keeps that document's status honest against this roadmap's horizons instead of
letting it drift as an unlinked, separately-tracked plan — the drift this
reconciliation (2026-08-22) found and fixed.
- Shipped (2026-07-23, ADR 0010): The N0–N4 use-case foundation and all ten
built-in workflow profiles — versioned profiles, corroborating artifacts,
explicit evidence relationships, signed handoff manifests, and consented
local aggregation — implemented through case schema v3 / packet v4, the CLI,
the localhost app, encrypted sync, and the verifier. Four profiles
(
repair_delivery,repair_comparison,utility_outage,displacement_expense) aremaintainer_reviewedand usable as shipped; six (inspector_handoff,accommodation_request,public_housing_remediation,health_corroboration,building_pattern,partner_capsule) are implemented but remainexternal_review_required— a named reviewer/partner gate, not an engineering gap. Availability is never presented as domain approval. - Shipped (2026-08-22, ADR 0012): Profile review-expiry enforcement. Closes a gap the foundation's own acceptance criteria named but left unenforced: selecting an already-expired profile is refused, and a profile that expires between selection and a later export no longer gets silently presented — export falls back to none and discloses why. This is what makes growing the profile registry (the item below) safe to do at all.
- Next use-case portfolio. Objective: keep adding new tenant/organizer
jobs on the same shared primitives instead of bespoke workflows, exactly as
ADR 0010 chose. Exit: see
docs/novel-use-cases-plan.md's "Beyond the current portfolio" section for the scored candidate set — a move-out/ deposit-dispute record and jurisdiction template growth are solo-buildable next; a joint multi-tenant case bundle is next after a presentation-only prototype; a protected-activity timeline is explicitly not queued until its own ADR settles a non-inference framing (it must never become a retaliation score —docs/novel-use-cases-plan.md's fit filter already excludes "landlord risk scores" and "automated judgments about truth"). - Named reviewer/partner recruitment for the six gated profiles.
Objective: convert
external_review_requiredintomaintainer_reviewedone profile at a time, on the record. Exit: a dated review recorded per profile indocs/capabilities.md, following the same recruitment kit (docs/recruitment/) already supporting the v1.0 gate's external reviews — this is a partnership problem shared with workstream D, not a separate one.
| Risk | Mitigation |
|---|---|
| Users treat a timestamp as proof of more than it shows (authorship, depiction) | The verifier and docs state the upper-bound semantics; packets and the README repeat it; Honest limits is prominent |
| Someone relies on it for a real case before it's audited | The alpha caveat is everywhere; v1.0 gate requires audit + pilot before the caveat is removed |
| Maintainer bus-factor (single steward) | Contributor onboarding, ADRs capturing rationale, shared-governance trigger, reproducible builds |
| A dependency or cryptographic primitive is compromised | Pinned/locked deps, pip-audit + CodeQL, well-reviewed primitives via cryptography, planned external review and provenance |
| Relay metadata exposes who-syncs-with-whom | Documented in the threat model; pure peer-to-peer needs no relay; metadata-resistance workstream |
| Overreach into legal advice | Explicit non-goal; framing reviewed by a lawyer as a v1.0 gate item |
The tool collects no usage data — by principle — so progress is measured by artifacts and outcomes, never by watching users:
- Audits completed (security, cryptographic, threat-model) and findings closed.
- Recorded AT passes with no open moderate+ findings.
- Pilots run and their written outcomes.
- Languages shipped (with enforced string parity) and jurisdiction templates added.
- Verifier robustness: fuzzing green; cross-checks against general-purpose RFC 3161 / hashing tools.
- Reproducible, signed releases.
If a metric would require instrumenting users, it is the wrong metric.
Per the portfolio OBSERVABILITY-STANDARD (which is tiered by deployment shape). This records habitable's values; the gates themselves live in the standard.
- CLI / library surface — Tier C. OTel tracing/metrics/SLOs are N/A: no network
surface (offline-first, local-only). Shipped (FIX-13): opt-in, on-device,
metadata-only structured logging (
src/habitable/obslog.py, mirroring the relay's_JsonFormatter/configure_logging).--log-format json— orHABITABLE_LOG=json— emits one JSON object per line to stderr at command boundaries (CLI) and redacted request boundaries (app server), carrying only counts, durations, booleans, and event names; it is off by default. The no-plaintext gate is absolute and pinned bytests/test_obslog.py(test_logs_never_leak_secrets_or_content): no filenames, paths, case/room/issue ids, passphrases, key material, request bodies, or media bytes ever reach the log stream —log_eventrefuses any non-scalar field so a payload cannot ride in. - Optional sync relay (
src/habitable/relay.py) — Tier A, with deliberate N/A-with-reason carve-outs driven by two hard project rules — no telemetry / no phone-home and a dependency-free relay image (stdlib only, small attack surface):
| Control (standard §) | habitable value |
|---|---|
| Structured JSON logs (§3) | Implemented, stdlib logging (no structlog dep). One JSON object per line: ts, level, msg, request_id, method, path, status, latency_ms. Per-request access log is opt-in (HABITABLE_RELAY_LOG=json), off by default. |
| PII/secrets-in-logs gate (§3, never N/A) | Enforced. Logs are metadata-only: no bodies, no keys, no peer IPs, and the room id is redacted to the route template /rooms/{room}. Pinned by tests/test_relay.py (test_access_log_never_leaks_room_id_key_or_payload) and the E2E-encryption guard in tests/test_sync.py. |
/livez + /readyz (§6) |
Implemented. /livez → 200 (no dep calls); /readyz fails closed (503) when the in-memory store is unhealthy; existing /healthz kept for aggregate counts. Probes excluded from the access log. |
| OTel traces (§1), RED/USE metrics (§2), SLOs (§4), burn-rate alerts (§5), collector/LGTM compose (§7) | N/A-with-reason: the relay must stay dependency-free and telemetry-free; adding OTel/OTLP exporters would contradict the no phone-home rule and enlarge the attack surface of a component whose whole point is that it can observe as little as possible. Trace correlation fields are omitted for the same reason. |
habitable will deliberately never:
- Host tenants' data, photos, or cases on a server the project controls.
- Run a central account system or any authority that can read or revoke a union's records.
- Add analytics, telemetry, or "anonymous" usage reporting.
- Promise admissibility or any court outcome, or become a substitute for legal advice.
- Weaken tamper-evidence or end-to-end encryption for convenience.
This file is revisited at each release and whenever a workstream item ships or a decision
changes. Significant decisions get an ADR in docs/adr/. Anything here that turns out to
violate a guiding principle is removed, not finessed. Progress is reflected in
CHANGELOG.md; this document is the why and the next, not the change log.