Release and data safety
Release safety concerns the actual bytes users receive. Data safety concerns whether diagnostics, logs, and request evidence disclose information that should not leave the environment.
In this section
- Signed manifests: bind release artifacts to size, SHA-256, signature, and channel data.
- PII redaction: handle secrets and personal data before display, persistence, or sharing.
- Request tracing: investigate Hub operations with timestamps, stable error codes, and correlation IDs.
Two independent evidence chains
Verifying an installer does not prove that runtime logs are redacted. A secret-free diagnostic bundle does not prove that an installer came from the correct release channel. Release and data owners should preserve their evidence separately and combine it at delivery time.
Before publishing or sharing, confirm provenance, version, channel, digest, signing state, data scope, redaction result, recipient, and retention period.
EvoX Docs · Security · Release and data safety