Skip to content
LCOS Write to us

Proofs

Facts,
not adjectives.

A guarantee without an artefact is a statement. This page cites only controls that have been executed, each tied to the piece that documents it. What has not been exercised does not appear here.

drill of 17/08/2026 · REQ-064 · AUD-000001

Three facts, three artefacts

21/21
fingerprints identical at the restoration drill of 17 August 2026
114 s
to restore the database from an encrypted off-site repository
0
deletions succeeded in the audit journal at the exercise of 17 August 2026

02

Every guarantee rests on a piece

  1. Append-only audit journal

    Deleting, altering or truncating an entry of the audit journal is rejected by database-engine triggers. Two roles were tested on 17 August 2026, against two distinct databases — we say so rather than conflate them. Against the production database, under the application role, which does not own the tables: alteration and truncation are refused by permissions, and disarming the trigger by ownership — “must be owner of table”. Against a disposable clone of that same database, under the superuser role: deletion was rejected by the trigger itself — “audit_events is append-only: DELETE is not permitted”. No attempt succeeded. This guarantee rests on an operating condition, which we state rather than leave unsaid: the application connects under a non-owner role; an owner of the table could disarm the trigger before writing.

    Artefacts: drill reports b2-p5-non-owner-role-2026-08-17 (non-owner application role, production database) and b2-p2-pitr-oldest-antitest-20260817, § 3.3 (trigger rejection under superuser, disposable clone) — hospitality-lcos repository, docs/audit.

  2. Restoration rehearsed, not promised

    On 17 August 2026 the database was restored to a point in time from an encrypted off-site repository, in 114 s. The 21 tables in scope returned 21/21 fingerprints identical to the expected set, 0 mismatches. The measured scope is that of the drill: surviving server, tooling in place.

    Artefact: drill journal b2-drill-pitr-20260817221349.json (canonical digests, cardinalities, measured duration).

  3. Approvals by role matrix

    A contract’s risk level determines which roles must decide, up to external counsel and executive management for the highest levels. Ratifying an approval rule emits a journalled event (APPROVAL_RULE_RATIFIED); an approver cannot approve their own request.

    Artefact: end-to-end test suite of the approval matrix (module 35), which verifies the event and its audit-journal entry.

  4. Stable, correlated errors

    A refusal from the system carries a stable error code: the same cause yields the same code, together with a correlation identifier tying the response to its journal entry.

    Artefact: stable-error catalogue of the master specification (§51); the repository’s test suites verify the codes returned.

03

The scope, stated in advance

These proofs are dated and can be replayed. They cover the perimeter exercised at their date — no more — and each new drill replaces a statement with a measurement.

LCOS runs a single chain: the counterparty, the deal, the matter, the contract, the approval. What it does not do is named here. It neither drafts nor generates any document; it holds no clause library, no contract template and no version comparison; it does not sign, and rests on no signature provider; it stores no file. The specification counts forty modules — it is named, and the count can be redone: `docs/superpowers/specs/2026-08-12-hospitality-lcos-master-spec.md` in the product repository. The repository carries nine application modules, which can be listed: counterparties, deals, matters, contracts, approvals, approval matrix, editorial firewall, audit journal, identity. These two counts are not subtracted one from the other, and we do not subtract them: a module of the repository does not map term for term onto a module of the specification. What remains on paper — media rights, finance, data protection, shared-service operation, international — is therefore not given a figure here. Enterprise authentication rests on a real adapter, which verifies the token against the provider’s public key set; what remains to be built is the connection to a corporate directory. The counterparty lifecycle stops at creation and reading. We would rather write this here than let it be discovered.

REQ-064 · 17/08/2026

04

The audit journal, append-only

None of these lines has been erased: deletion, alteration and truncation are rejected by the database engine itself. On 17 August 2026 two roles were tested against two databases: the application role, which does not own the tables, against production, and the superuser role against a disposable clone of it. No attempt succeeded.

  1. 2026-08-17T22:13:49Z drill-pitr-20260817221349 Witness point created, then restored from the encrypted off-site repository.
  2. 2026-08-17T22:15:45Z 21/21 · 114 s Database restored: fingerprints identical to the expected set, 0 mismatches.
  3. 2026-08-17T22:16:27Z b2-drill-oldest-20260817221627 The oldest backup replayed in its turn.

Reference of a journal entry: AUD-000001. Ratification of an approval rule: APPROVAL_RULE_RATIFIED (MODULE 35). Resilience requirement: REQ-064.

What is built, and what is not

MODULE 35 · REQ-064 · AUD-000001

E&HADS AGENCY, a French simplified joint-stock company with a sole shareholder, share capital 1,000 euros, registered with the Saintes trade and companies registry under number 932 700 271 (registered on 10 September 2024), European identifier FR1708.932700271, registered office 2 impasse de Monouge, 17240 Mosnac, France. Publication director: Deo Gracia Metoyer. Publisher’s telephone: +33 6 59 71 33 77. Host: Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, United States, telephone +1 888 993-5273.

Legal notice Français