Scrutiny

Direct questions,
bounded answers.

Each answer is labeled by evidence status so implemented behavior, customer contract, product direction, and unresolved questions are not blended together.

On this page
Status key
Current

Present in the inspected product or runtime source. Deployment still requires version-specific validation.

Contract

A documented customer-facing boundary or responsibility. A signed agreement takes precedence.

Direction

An intended product path, not a current universal capability or delivery commitment.

Unknown

Not established by the reviewed source, documentation, or published run evidence.

Current

Who can approve a new runtime release?

The Trust Console keeps the customer approval key on the customer machine and signs exact hashes. Manual and allowlist modes preserve a practical customer veto; auto signs every control-plane-requested hash and gives up that per-release veto while enabled.

Current

Does Infraveil need custody of application source?

Not for no-source attach. A fresh attach creates a manifest-only active package. Source-custody mode can package application files, and changing modes does not by itself prove that older hosted files were removed.

Current

Does “no-source” mean nothing is stored on disk?

No. The runtime stores the manifest/package and can store local state, caches, logs, receipts, runtime dependencies, and customer-configured persistent paths. Inspect the actual host paths and cleanup behavior.

Current

What happens if the hosted plane is unavailable?

Customer-side workloads may continue from explicit current or cached state. New coordination, approvals, reporting, and revocation delivery can be delayed. Continuity depends on the local state and workload configuration; it is not guaranteed.

Current

Does the gateway protect all application traffic?

No. Its controls apply to traffic that traverses configured managed routes. Direct origin access, an alternate listener, or another network path can bypass it unless the customer restricts those paths.

Current

Is this upstream DDoS protection?

Not by the gateway alone. Infraveil-hosted public endpoints currently use OVHcloud upstream Anti-DDoS infrastructure and Cloudflare for configured proxied web traffic, while the gateway applies origin-side controls to managed routes. Those provider layers do not cover every customer workload, direct origin address, unproxied hostname, non-HTTP service, or bypass listener. Customer deployments should retain appropriate upstream mitigation and restrict direct origin access.

Contract

What remains the customer's responsibility?

Application correctness, host hardening, infrastructure accounts, network exposure, dependencies, secrets, persistent data, backups, capacity, health definitions, recovery compatibility, user access, and workload-specific incident response remain customer responsibilities unless an applicable agreement says otherwise.

Contract

What does a receipt mean?

A receipt records a defined step and its reported state. Intent, customer approval, byte integrity, process execution, health, reachability, and recovery are separate facts. The signed agreement and current product documentation define the applicable retention and support boundary.

Direction

Will every operational tool be replaced?

That is not a product commitment. The direction is to reduce coordination across deployment, runtime supervision, gateway policy, evidence, incidents, and recovery where one operating model adds value. Specialty tools may remain appropriate.

Direction

Are self-hosted management and full air gap planned?

Private deployment options can be evaluated as product direction, but this page does not present a self-hosted management plane or full air-gap operation as a current universal capability.

Unknown

What reliability has the Validation Protocol demonstrated?

No request-bearing reliability result is established by the checked-in record. The only checked-in attempt is a failed zero-request smoke run. The Validation Protocol defines the evidence a future run should publish.

Unknown

Which enterprise controls are universally available?

Fine-grained RBAC, SSO/SCIM, SOC 2 status, data residency, contractual SLA, regional topology, and support-access details are not established here as current universal capabilities. Confirm each requirement for the current offering and agreement.

How to resolve an unknown

Ask for the record that matches the claim.

For runtime behavior, request a dated execution bundle. For hosted controls, request current product documentation and contractual terms. For a delivered component, inspect its exact source and hash. If the evidence cannot distinguish intent, execution, and outcome, keep the answer unknown.