> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/security-compliance.md).

# Security & Compliance

> Cumulative security posture and GDPR compliance record. Updated between phases via carryforward. **Line budget**: 1000 max | **Last updated**: Phase 24 (2026-07-08)

***

## Current Security Posture

### Overall: AT RISK

Phase 24 completed Legion II - Live Tier And Combat Playback with security PASS for all nine `apps/web`-centered sessions. The phase added projection- owned live enemy presentation, camp-to-mission linkage, combat playback, scrying, alert focus, world cues, prompt-link persistence scrubbing, typed generated-asset references, and final documentation without opening new findings. The cumulative posture remains AT RISK because older claim-boundary findings for hosted identity, trusted erasure, production-hosted validation, custom-domain Cloudflare smoke evidence, and formal legal/privacy approval remain open.

| Metric           | Value                                                |
| ---------------- | ---------------------------------------------------- |
| Open Findings    | 5                                                    |
| Critical/High    | 0                                                    |
| Medium/Low       | 5                                                    |
| Phases Audited   | 24                                                   |
| Last Clean Phase | P24 for phase scope; cumulative findings remain open |

***

## Open Findings

Active security or GDPR issues requiring attention. Ordered by severity.

### Critical / High

No open Critical or High findings.

### Medium / Low

* **\[P06-S07-HOSTED-IDENTITY] Hosted identity remains no-claim**
  * Severity: Medium
  * File: `apps/warroom`, `apps/web`, `packages/protocol`, docs
  * Description: Room-local Worker-issued bearer authority is not hosted account identity, SSO, organization membership, public collaboration safety, or production auditability.
  * Remediation: Keep open/no-claim unless active hosted auth is shipped with account identity, authorization, consent, revocation, audit, abuse controls, local fallback, tests, and docs.
  * Status: Open
  * Opened: P06 (2026-05-29)
* **\[P06-S07-ERASURE] Trusted unified erasure remains no-claim**
  * Severity: Medium
  * File: `apps/warroom`, `apps/web`, archives, logs, backups
  * Description: Phase 24 proves browser-local projection cleanup only for scoped local keys; it still does not prove broad trusted deletion for hosted, replay, push, remote, workspace-file, backup/log/archive, or future surfaces.
  * Remediation: Close only after every claimed boundary has dry-run, confirmation, execution, idempotency, partial-failure handling, redacted audit, and verification evidence.
  * Status: Open
  * Opened: P06 (2026-05-29)
* **\[P06-S07-HOSTED-VALIDATION] Production-hosted validation remains no-claim**
  * Severity: Low
  * File: release docs, hosted deploy checks
  * Description: Local and no-network evidence exists, but deployed public website, public demo, Worker, and optional app-shell claims remain blocked without safe live validation and owner-managed custom-domain access.
  * Remediation: Keep production-hosted claims out of release copy until sanitized live smoke passes for claimed deployed targets.
  * Status: Open
  * Opened: P06 (2026-05-29)
* **\[P16-S05-CLOUDFLARE-DEPLOY] Authorized Cloudflare custom-domain smoke is unavailable**
  * Severity: Low
  * File: `.spec_system/audit/known-issues.md`, `.github/workflows/*deploy*.yml`, `docs/deployment.md`, `docs/release.md`
  * Description: Phase-transition deploy and local gates passed, but custom-domain smokes on 2026-07-05 returned HTTP 403 or HTTP\_STATUS for `faction-os.com`, `demo.faction-os.com`, and `warroom.faction-os.com/health`; resolution requires Cloudflare/domain/WAF access.
  * Remediation: Keep live hosted-health claims as no-claim until an authorized environment reruns public website, demo, and War Room smokes successfully.
  * Status: Open
  * Opened: P16 (2026-06-02)
* **\[P16-S05-LEGAL-REVIEW] Formal legal/privacy owner approval is pending**
  * Severity: Low
  * File: `.spec_system/specs/phase16-session05-launch-review-and-documentation-handoff/security-compliance.md`, `docs/release.md`
  * Description: The launch handoff keeps privacy and legal pages visibly pre-review, but no formal owner approval is recorded yet.
  * Remediation: Record owner approval before changing copy from pre-review to approved launch language.
  * Status: Open
  * Opened: P16 (2026-06-02)

***

## GDPR Compliance Status

### Overall: AT RISK

Phase 24 added browser-local aggregate live-tier and combat presentation state derived from local event streams and Quest Board actions. Runtime pending links may contain bounded prompts for active mission matching, but persisted `localStorage["factionos-game-v1"]` snapshots scrub `pendingLinks`, and legacy persisted raw links normalize away on load. The phase added no new personal data collection, hosted persistence, third-party transfer, analytics, account identity, consent flow, or trusted-erasure claim. GDPR is PASS/N/A for the phase scope, while cumulative posture remains AT RISK because trusted unified erasure and hosted identity remain explicit no-claims.

### Personal Data Inventory

| Data Element                                               | Package                                                                                                   | Source                                                                                                                                                                | Storage                                                                                                                                                                                             | Purpose                                                                                                                                                 | Legal Basis                                             | Retention                                                                                                     | Deletion Path                                                                                                                                   | Since           |
| ---------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- | --------------- |
| Browser preferences and UI state                           | `apps/web`                                                                                                | Local browser settings and transient UI state                                                                                                                         | `localStorage` for durable preferences; runtime store for transient overlays                                                                                                                        | Theme, audio, reduced motion, notifications, scan roots, replay panel state, focused bottom-rail surface state, faction selection, and local auth hints | Local user configuration                                | Durable preferences until browser storage is cleared; transient overlays until close/reset/reload             | Browser storage deletion/reset today; transient state clears in memory; full trusted erasure remains no-claim                                   | P02/P21         |
| Derived game projection aggregate                          | `apps/web`                                                                                                | Local event stream folded by `gameProjection.ts`; runtime-only pending camp-link prompts                                                                              | Runtime store and browser `localStorage["factionos-game-v1"]` with `pendingLinks` scrubbed before persistence                                                                                       | Local game projection, attention, enemy state, camp-link readiness, replay-safe browser re-entry, live-tier presentation, and combat playback evidence  | Local user operation                                    | Until reset, browser-local erasure, or manual storage removal; prompt-bearing pending links stay runtime-only | `resetToSeed()`, `executeBrowserErasure()`, or manual browser storage clear; full trusted erasure remains no-claim                              | P22/P24         |
| Scanner camp projection aggregate                          | `apps/web`                                                                                                | Local Quest Board scanner snapshots and codebase issue ids folded through `legionCamps.ts`                                                                            | Runtime store and browser `localStorage["factionos-game-v1"]`                                                                                                                                       | Battlefield scanner camps, safe sector fronts, Quest Board camp focus, dry Banish source mapping, Golden Age, and scanner-state presentation            | Local user operation                                    | Until reset, browser-local erasure, manual storage removal, or a real clean scanner snapshot clears camps     | `resetToSeed()`, `executeBrowserErasure()`, manual browser storage clear, or real clean scanner snapshot; full trusted erasure remains no-claim | P23             |
| Replay snapshots and share fragments                       | `apps/web`                                                                                                | Local runtime state                                                                                                                                                   | Browser state and URL fragments                                                                                                                                                                     | Local replay review and share links                                                                                                                     | Local user action                                       | Until browser state/link is cleared                                                                           | Manual deletion today; full trusted erasure remains no-claim                                                                                    | P02             |
| Session exports and archive data                           | `apps/web`, `apps/server`                                                                                 | Local session state                                                                                                                                                   | Download/export and filesystem archive                                                                                                                                                              | Developer portability and review                                                                                                                        | Local user action                                       | Local files retained by user                                                                                  | Manual deletion today; full trusted erasure remains no-claim                                                                                    | P01             |
| Codebase scan inputs and outputs                           | `apps/web`, `apps/server`                                                                                 | Approved local roots and local scanner results                                                                                                                        | Local scan request/response, runtime scanner state, and local manager state                                                                                                                         | Local diagnostics, Quest Board issue review, and scanner camp source data                                                                               | Local user action                                       | Request-scoped unless persisted in Quest Board state, exports, or logs                                        | Manual deletion today; full trusted erasure remains no-claim                                                                                    | P02/P23         |
| Local orchestration and command-center state               | `packages/protocol`, `apps/server`, `apps/web`, `apps/cli`, `apps/hooks`, `apps/adapters`, `apps/warroom` | Local queue, campaign, template, lineage, guarded-action, attention, executor, artifact, handoff, channel, metric, notification, and release-evidence events          | In-memory managers, compact browser state, local diagnostics, hook/listener logs, scoped local runtime state, and tracked release evidence                                                          | Local orchestration visibility, review, audit, release proof, and diagnostics                                                                           | Local user operation                                    | Runtime/local-state lifetime, or repository history for tracked evidence                                      | Manual cleanup and narrow recovery today; full trusted erasure remains no-claim                                                                 | P03/P19/P20/P21 |
| File/Git execution metadata                                | `apps/server`, `apps/web`, `apps/hooks`                                                                   | Local file intents, repo-relative mutation requests, Git proposals, hook attribution, guarded-action decisions, backup ids, rollback metadata, and compact Git counts | Local command-center records, file mutation manager state, backup metadata, and browser state                                                                                                       | File conflict protection, local file execution, Git preview/execution review, rollback, and local audit                                                 | Local user operation                                    | Runtime/local-state lifetime; backups follow local backup retention                                           | Manual reset/delete of local state and backups; full trusted erasure remains no-claim                                                           | P19/P20         |
| Terminal/container runtime metadata                        | `apps/server`, `apps/web`                                                                                 | Local terminal/container actions, PTY/container readiness probes, isolated-spawn results, and compact unavailable/failure summaries                                   | Server runtime session buffers, bounded execution attachments, and scoped web drawer state                                                                                                          | Local terminal/container capability, execution, recovery, and diagnostics                                                                               | Local user operation                                    | Runtime/session lifetime unless exported/logged elsewhere                                                     | Kill/reset local sessions and clear local state; full trusted erasure remains no-claim                                                          | P19/P20         |
| Managed-agent lifecycle metadata                           | `apps/server`, `apps/web`                                                                                 | Locally manager-owned process or PTY lifecycle actions and compact results                                                                                            | Managed session manager runtime state, command-center records, and browser state                                                                                                                    | Stop, restart, and message control for FactionOS-owned local sessions                                                                                   | Local user operation                                    | Runtime/session lifetime unless exported/logged elsewhere                                                     | Stop/reset local session state; full trusted erasure remains no-claim                                                                           | P20             |
| Channel command and template metadata                      | `packages/protocol`, `apps/server`, `apps/web`, `apps/adapters`                                           | Local inbound webhook/channel records, source-owned template defaults, local conversion decisions, and adapter attribution                                            | In-memory replay maps, local command-center records, and browser state                                                                                                                              | Proposal-first command review, local queue-task conversion, source attribution, and duplicate prevention                                                | Local user operation                                    | Runtime/local-state lifetime                                                                                  | Existing local reset/erasure flows; no hosted storage added                                                                                     | P19/P20         |
| Notification preferences and Web Push subscription summary | `apps/server`, `apps/web`                                                                                 | Operator settings and browser subscription after consent                                                                                                              | Local command-center state; endpoint hash and key lengths only                                                                                                                                      | Local notification routing, readiness, and subscription status                                                                                          | Consent/local user operation                            | Until unsubscribe, preference update, or local reset                                                          | Unsubscribe route or preference update; full trusted erasure remains no-claim                                                                   | P19             |
| Quest Board suggestion store and summaries                 | `apps/server`, `apps/web`                                                                                 | Relative file paths, code-derived titles/messages/prompts, IDs, timestamps, dismissed IDs, summary counts, and scan status                                            | Local file under `FACTIONOS_HOME` or `~/.factionos`; web runtime/browser state for focused camp filters and runtime-only pending mission links                                                      | Quest Board suggestion persistence, issue review, scanner camp inspection, dry Banish target selection, and camp-to-mission linkage                     | Local user operation                                    | Until the file is deleted, dismissed, migrated, or local runtime state is cleared                             | Manual delete of `suggestions.json` and browser state reset; full trusted erasure remains no-claim                                              | P18/P24         |
| Quest Board analysis and project scan results              | `apps/server`                                                                                             | Safe relative code-file selections, sanitized workspace summaries, and manager-owned scan results                                                                     | Runtime memory and local manager-owned state                                                                                                                                                        | Local diagnostics and strategic follow-up                                                                                                               | Local user operation                                    | Request-scoped unless persisted                                                                               | Manual local deletion or manager reset; full trusted erasure remains no-claim                                                                   | P18             |
| Local backup archives                                      | `scripts`, `apps/server`                                                                                  | Existing FactionOS home state and file mutation backups                                                                                                               | Local tarballs under `~/.factionos/backups/` or `FACTIONOS_BACKUP_DIR`; file mutation backup metadata                                                                                               | Local state preservation, file mutation rollback, and recovery                                                                                          | Local user action                                       | `FACTIONOS_BACKUP_RETENTION_DAYS`, default 30 days, unless manager-specific retention differs                 | Manual deletion today; full trusted erasure remains no-claim                                                                                    | P03/P20         |
| Redacted operational logs                                  | `apps/server`, `apps/cli`                                                                                 | Local runtime events and errors                                                                                                                                       | Ignored `logs/` directory or `FACTIONOS_LOGS_DIR`                                                                                                                                                   | Local diagnosis of startup, shutdown, and command failures                                                                                              | Local legitimate interest/user operation                | Manual/local retention today                                                                                  | Delete local log directory; full trusted erasure remains no-claim                                                                               | P03             |
| War Room room data and browser hints                       | `apps/warroom`, `apps/web`, `packages/protocol`                                                           | Optional room lifecycle, participant display metadata, health diagnostics, room-local authority metadata, and redacted federation events                              | Cloudflare Durable Object storage when deployed and used; browser localStorage stores bounded Worker URL and participant hints; raw authority tokens remain browser-memory request credentials only | Optional room collaboration and diagnostics                                                                                                             | User-configured optional Worker URL and local operation | Worker room/runtime lifetime; browser hints until cleared                                                     | Browser leave/reset clears local room context only; full trusted erasure remains no-claim                                                       | P06             |
| Media catalog and draft provenance                         | `packages/protocol`, `apps/web`, `assets`, `public-demo`, `scripts`, `public-website`                     | Local media records, generated Phase 3 source-sheet references, copied website asset records, and redacted draft planning                                             | Tracked catalog fixtures, package-local website media registry, generated asset map, draft manifest, docs, and local evidence; raw provider outputs remain ignored staging                          | Media provenance, generated asset implementation handoff, fallback posture, and release gating                                                          | Local project documentation and validation              | Until repository docs/history change                                                                          | Remove or revise tracked docs; broader decommission remains governed by release records                                                         | P04/P24         |

### Compliance Checklist

| Requirement                            | Status                      | Notes                                                                                                                                                                                                                                                                                          |
| -------------------------------------- | --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Data collection has documented purpose | PASS                        | Existing local browser state, exports, scans, orchestration diagnostics, backups, logs, optional War Room metadata, media provenance, Quest Board data, local execution/release metadata, derived projection state, scanner camps, and Phase 24 live-tier aggregates have documented purposes. |
| Consent obtained before data storage   | PASS                        | Worker transfer is optional and user-configured; Web Push subscription handling requires consent/readiness; backup, local execution, file mutation, local channel conversion, browser-local projection, scanner camp, and live-tier actions are local user operations.                         |
| Data minimization verified             | PASS                        | Phase 24 persists aggregate projection records only; prompt-bearing pending links stay runtime-only, generated source paths do not become runtime media URLs, and raw prompts, outputs, provider payloads, broad paths, and secrets are excluded by tests and docs.                            |
| Deletion/erasure path exists           | PASS with residual no-claim | Manual deletion/reset exists for local files, backups, runtime state, Quest Board state, and browser state; Phase 24 reused projection reset/browser-local erasure and scrubbed pending links, but full trusted unified erasure remains no-claim.                                              |
| No PII in application logs             | PASS                        | Phase 24 reports confirmed no new logging path for raw issue text, prompt, token, path, transcript, terminal output, file content, Worker authority, provider payload, generated source art, scanner camp, or projection payload data.                                                         |
| Third-party transfers documented       | PASS                        | Phase 24 added no third-party transfer path and preserved hosted identity, hosted storage, remote execution, production-hosted validation, formal certification, and trusted erasure no-claims.                                                                                                |

***

## Dependency Security

### Current Vulnerabilities

No known vulnerable dependencies from the reviewed phase scope.

Phase 24 dependency notes:

* No dependency package additions or dependency version changes were introduced.
* `apps/web` package version bumps were release/version synchronization only.
* Generated Phase 3 visual sheets are typed source references and blocked media catalog records, not browser-loaded runtime assets.
* Focused Phase 24 tests, root tests, web/workspace typechecks, format check, lint, secret scans, generated asset catalog checks, generated source-path runtime scans, ASCII/LF checks, and dependency/package diff checks passed where recorded.

***

## Resolved Findings

Recently closed items. Compressed after 2 phases.

| ID                      | Finding                                                                 | Severity | Resolved   | Phase | Resolution                                                                                                                      |
| ----------------------- | ----------------------------------------------------------------------- | -------- | ---------- | ----- | ------------------------------------------------------------------------------------------------------------------------------- |
| P19-S12-WRANGLER-UNDICI | Transitive `wrangler -> miniflare -> undici` audit vulnerability        | High     | 2026-06-26 | P19   | Updated Wrangler/Miniflare/Undici/Workerd lockfile and allow-scripts metadata; final moderate audit reported 0 vulnerabilities. |
| P13-S01-ASTRO-CHECK     | Astro checker dependency pulled vulnerable YAML language-server subtree | Medium   | 2026-06-01 | P13   | Removed `@astrojs/check`, switched typecheck to `astro sync && tsc --noEmit`, and validated audit results.                      |
| P03-S07-LOGGING         | Logger captured sensitive context before redaction                      | Medium   | 2026-05-29 | P03   | Added server/CLI redaction for secret-like keys, bearer strings, URLs, repo/home paths, and argv values.                        |
| P03-S07-ASCII           | Startup console output used non-ASCII characters                        | Low      | 2026-05-29 | P03   | Converted server banner and shutdown message to ASCII-only output and reran ASCII/LF validation.                                |

***

## Phase History

| Phase | Sessions                                                                                | Security                                 | GDPR                                         | Findings Opened | Findings Closed |
| ----- | --------------------------------------------------------------------------------------- | ---------------------------------------- | -------------------------------------------- | --------------- | --------------- |
| P24   | 9 mostly `apps/web`                                                                     | PASS for phase scope; cumulative AT RISK | PASS/N/A for phase scope; cumulative AT RISK | 0               | 0               |
| P23   | 8 `apps/web`                                                                            | PASS for phase scope; cumulative AT RISK | PASS/N/A for phase scope; cumulative AT RISK | 0               | 0               |
| P22   | 8 `apps/web`                                                                            | PASS for phase scope; cumulative AT RISK | PASS for phase scope; cumulative AT RISK     | 0               | 0               |
| P21   | 7 `apps/web`                                                                            | PASS for phase scope; cumulative AT RISK | PASS/N/A for phase scope; cumulative AT RISK | 0               | 0               |
| P20   | 11 cross-cutting (`packages/protocol`, `apps/server`, `apps/web`, `apps/cli`, docs/e2e) | PASS for phase scope; cumulative AT RISK | PASS/N/A for phase scope; cumulative AT RISK | 0               | 0               |

***

## Recommendations

1. Keep live-tier and combat playback projection-owned and presentation-only; future battlefield, ceremony, report, audio, or reward work should not add parallel game state, storage keys, server routes, protocol events, or reward authority without a scoped phase.
2. Preserve runtime-only pending-link prompts, persisted `pendingLinks` scrubbing, legacy normalization, and the single `factionos-game-v1` storage key.
3. Promote generated Phase 3 sheets to browser runtime only through app-owned paths, slicing, optimization, metadata cleanup, accessibility review, and media gates.
4. Resolve Cloudflare/domain/WAF access and rerun public website, public demo, and War Room custom-domain smokes before claiming hosted health.
5. Continue dependency, secret, ASCII/LF, format, typecheck, lint, focused privacy, generated asset, projection, local-erasure, and broad UI checks after native runtime, Worker tooling, package manifest, release-doc, projection, scanner, combat, audio, or media changes.
6. Keep the cumulative AT RISK language until hosted identity, trusted unified erasure, production-hosted validation, authorized Cloudflare custom-domain smoke evidence, and formal legal/privacy approval are explicitly closed.

***

## Notes

* Phase 24 shipped local browser live-tier and combat playback presentation for existing event and Quest Board evidence; it did not add hosted persistence, new protocol events, new server routes, third-party transfer, rewards, XP, loot, banners, public-demo synthetic fronts, broad generated-media serving, or trusted-erasure claims.
* Every Phase 24 session security report passed. No unresolved Phase 24 security or GDPR findings remain.
* Browser-local erasure of projection aggregates through `factionos-game-v1` is not production-hosted validation, formal certification, hosted identity proof, or trusted unified erasure proof.
* Open findings remain claim-boundary issues, not active new Phase 24 vulnerabilities.

***

*Auto-generated by carryforward. Direct edits allowed but may be overwritten.*


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/security-compliance.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
