Proofs
Facts,
not adjectives.
A guarantee without an artefact is a statement. This page cites only controls that have been executed, each tied to the piece that documents it. What has not been exercised does not appear here.
drill of 17/08/2026 · REQ-064 · AUD-000001
Three facts, three artefacts
- 21/21
- fingerprints identical at the restoration drill of 17 August 2026
- 114 s
- to restore the database from an encrypted off-site repository
- 0
- deletions succeeded in the audit journal at the exercise of 17 August 2026
02
Every guarantee rests on a piece
-
Append-only audit journal
Deleting, altering or truncating an entry of the audit journal is rejected by database-engine triggers. Two roles were tested on 17 August 2026, against two distinct databases — we say so rather than conflate them. Against the production database, under the application role, which does not own the tables: alteration and truncation are refused by permissions, and disarming the trigger by ownership — “must be owner of table”. Against a disposable clone of that same database, under the superuser role: deletion was rejected by the trigger itself — “audit_events is append-only: DELETE is not permitted”. No attempt succeeded. This guarantee rests on an operating condition, which we state rather than leave unsaid: the application connects under a non-owner role; an owner of the table could disarm the trigger before writing.
Artefacts: drill reports b2-p5-non-owner-role-2026-08-17 (non-owner application role, production database) and b2-p2-pitr-oldest-antitest-20260817, § 3.3 (trigger rejection under superuser, disposable clone) — hospitality-lcos repository, docs/audit.
-
Restoration rehearsed, not promised
On 17 August 2026 the database was restored to a point in time from an encrypted off-site repository, in 114 s. The 21 tables in scope returned 21/21 fingerprints identical to the expected set, 0 mismatches. The measured scope is that of the drill: surviving server, tooling in place.
Artefact: drill journal b2-drill-pitr-20260817221349.json (canonical digests, cardinalities, measured duration).
-
Approvals by role matrix
A contract’s risk level determines which roles must decide, up to external counsel and executive management for the highest levels. Ratifying an approval rule emits a journalled event (APPROVAL_RULE_RATIFIED); an approver cannot approve their own request.
Artefact: end-to-end test suite of the approval matrix (module 35), which verifies the event and its audit-journal entry.
-
Stable, correlated errors
A refusal from the system carries a stable error code: the same cause yields the same code, together with a correlation identifier tying the response to its journal entry.
Artefact: stable-error catalogue of the master specification (§51); the repository’s test suites verify the codes returned.
03
The scope, stated in advance
These proofs are dated and can be replayed. They cover the perimeter exercised at their date — no more — and each new drill replaces a statement with a measurement.
LCOS runs a single chain: the counterparty, the deal, the matter, the contract, the approval. What it does not do is named here. It neither drafts nor generates any document; it holds no clause library, no contract template and no version comparison; it does not sign, and rests on no signature provider; it stores no file. The specification counts forty modules — it is named, and the count can be redone: `docs/superpowers/specs/2026-08-12-hospitality-lcos-master-spec.md` in the product repository. The repository carries nine application modules, which can be listed: counterparties, deals, matters, contracts, approvals, approval matrix, editorial firewall, audit journal, identity. These two counts are not subtracted one from the other, and we do not subtract them: a module of the repository does not map term for term onto a module of the specification. What remains on paper — media rights, finance, data protection, shared-service operation, international — is therefore not given a figure here. Enterprise authentication rests on a real adapter, which verifies the token against the provider’s public key set; what remains to be built is the connection to a corporate directory. The counterparty lifecycle stops at creation and reading. We would rather write this here than let it be discovered.
REQ-064 · 17/08/2026
04
The audit journal, append-only
None of these lines has been erased: deletion, alteration and truncation are rejected by the database engine itself. On 17 August 2026 two roles were tested against two databases: the application role, which does not own the tables, against production, and the superuser role against a disposable clone of it. No attempt succeeded.
- 2026-08-17T22:13:49Z drill-pitr-20260817221349 Witness point created, then restored from the encrypted off-site repository.
- 2026-08-17T22:15:45Z 21/21 · 114 s Database restored: fingerprints identical to the expected set, 0 mismatches.
- 2026-08-17T22:16:27Z b2-drill-oldest-20260817221627 The oldest backup replayed in its turn.
Reference of a journal entry: AUD-000001. Ratification of an approval rule: APPROVAL_RULE_RATIFIED (MODULE 35). Resilience requirement: REQ-064.