BRIEF-39A3B6D2revision 20 August 2026commit 756c429checkpoint a9432068platform 1.0.0-trial1Internal · Controlled Distribution

NO-GO for live lender assignments.

Connecting the custom domain must not be read as the moment the system becomes live. Four prerequisites are unmet: MFA, malware scanning with a licensed engine, a rehearsed backup and restore drill, and database-level protection of the audit tables.

Live assignments · withheldSandbox on synthetic data · permitted

Prepared for Executive sponsor, CTO, counsel and the Trial 1 decision board. Every figure below is derived from the same registers the long-form record renders — nothing on this page is retyped, so it cannot drift from the detail behind it.

01 · The numbers a decision rests on

0

Production-class records

No real lender file has ever run through the platform.

source · Readiness build record

0

Blocking gates open

Every one must read GREEN before the first live assignment. 19 board gates are RED.

source · Trial 1 readiness gates

0

Non-waivable P0 items

Scheduling durability, restore drill, malware scanning, audit-table grants, MFA, tenant isolation.

source · Patch 1.2 hardening register

0

Controls proven

Against 68 keyed requirements and 1 GREEN matrix verdict — proven means evidence exists, not that a document claims it.

source · Hardening + readiness control registers

0

Audit entries chained

Linkage intact, zero breaks. Verify it yourself on /proof rather than trusting this line.

source · Platform state at record time

$0.00B

Addressable software spend

Against $1T+ of receivables routed through cloud recovery platforms each year.

source · Market reference register

02 · What is being asked, in order

  1. ask 01Executive sponsor

    Approve external sandbox testing

    Synthetic and trial data only, controlled accounts, no lender file. This is the decision that is actually available today.

  2. ask 02CTO

    Assign owners to the blocking gates

    10 of 10 blocking gates currently carry no named owner. An unowned gate does not close.

  3. ask 03Engineering

    Fund the P0 hardening pass

    Durable scheduling and monitoring, rehearsed restore, licensed malware scanning, database-level audit grants, MFA, proven tenant isolation.

  4. ask 04Decision board

    Withhold live-trial approval

    No executive risk acceptance substitutes for a missing safety, identity, isolation or restore control. Re-present when the board sheet is GREEN.

03 · Risks that would end the trial, not delay it

#RiskSeverityLikelihood
01

Wrongful or continued recovery after recall/cure/bankruptcy/legal hold

Safety, legal and reputational harm; stop-work behavior is visible but end-to-end server/notification proof is absent.

CriticalPossible
02

Silent scheduler/deadline failure after deploy, restart or idle

Prior CTO record explicitly describes this failure mode; UI health does not prove external detection or durable execution.

CriticalLikely until closed
03

Cross-tenant lender/vendor exposure

External accounts and hostile tenant tests are explicitly unproven; portals contain high-value VIN, assignment, document and financial data.

CriticalPossible

04 · Newest material findings

NF-01

Public HTML loads both Umami and Plausible.

A second collector contradicts the understood Umami-only posture and may receive operational routes.

dispositionDisable all analytics on authenticated origins or prove strict public-route allowlisting for every collector; purge prior sensitive paths.

NF-02

Umami suppression is a client monkey-patch applied to a finite sensitive-route denylist.

Initial pageviews, future routes, Plausible, referrers, page titles and provider retention are not proven controlled.

dispositionDefault deny; initialize analytics only on an allowlist of public routes; network/provider tests.

NF-03

Assignment URLs use an internal ID, while references/VINs appear in page content.

The specific reference-in-path claim is reduced, but the internal ID remains sensitive and titles/referrers may still leak.

dispositionTemplate/redact paths and suppress title/referrer; never emit identifiers/properties.

NF-04

Auth client reads sessionStorage manus-cookie/app_session_id and sends it as Bearer authorization.

A JavaScript-readable bearer fallback weakens an httpOnly-only session posture and increases XSS impact.

dispositionExplain provenance/necessity; remove for production if possible; threat-model and test token exposure, rotation and revocation.

05 · Governing test

Do not ask whether the software has a feature. Ask whether the system can prove the control works when something goes wrong.

The next phase is proof and hardening. A real recovery assignment should not enter until the Go/No-Go board is GREEN on durable scheduling and monitoring; stop-work propagation; MFA and privileged actions; external tenant isolation; analytics privacy; upload quarantine; database audit permissions; backup/restore; domain/OAuth/session and auth-provider continuity; incident/on-call readiness; company ownership; metric baseline; and current critical-bug status. Until then, no polished interface, summary statistic or test claim should be allowed to convert UNKNOWN into GREEN.

BRIEF-39A3B6D2 · this identifier changes whenever any figure above changes