--- id: RISK-V-0003 type: verification title: "Owner-source progress and outstanding runtime evidence" date: "2026-09-05" owner: risk-nexus workplan: RISK-WP-0007 findings: [RISK-F-0011, RISK-F-0010, RISK-F-0008] --- # Owner-source review — 2026-09-05 This is a checkout and inbox review, not a runtime probe. No credentials were used or reproduced, no system was changed and no legal determination was renewed. Files can include uncommitted owner work; repository HEAD is context, not proof that every inspected change is in that commit. ## Qonto deny-stream completeness Read State Hub notice `c6442eef-34fc-46a7-9639-10f2cd6120fc` (2026-09-04), QONTO-WP-0005, `specs/audit-emission-cadence.yaml`, `src/qonto_assistant/audit.py`, the application lifespan/reconciliation endpoint, and KG-WP-0005. The source now declares process instance/sequence semantics, a 24-hour default active-process heartbeat, startup and best-effort shutdown, and reconciliation counts. AuditLogger serializes emission and exposes source counters; the app wires the heartbeat lifecycle and identity-checked snapshot route. Qonto records 88 passing tests on its latest review; that suite was not rerun by risk-nexus. King's Guard records local source-path validation and explicitly leaves KG-WP-0005-T03 waiting for authorized deployed evidence. **Conclusion:** the old statement that no source cadence/reconciliation exists is obsolete. Runtime completeness remains unestablished. F-0011 stays open, medium and public, with QONTO-WP-0005 and KG-WP-0005-T03 as tracking. **Closure evidence owed:** qonto's runtime owner supplies a bounded capture from one deployed instance, naming the deployed revision, configured heartbeat interval and observation window. It covers startup, a request transition, periodic heartbeat timing, sequence/instance continuity and a same-instance reconciliation snapshot. King's Guard compares received counts and source counts, records any gaps and the acceptance decision. Evidence may support only the observed instance/window, never an unbounded all-time completeness claim. The original 2026-09-16 default remains; a completed source plan does not close the runtime finding. This narrows the existing evidence request; no new request or message was sent in this sitting. ## Backup credential Read RPF-WP-0029 and inspected `tools/cmd/forgejo-backup` in memory for the named shell fallback without outputting credential-bearing lines. No nonempty literal fallback for `RAILIANCE_BACKUP_NC_TOKEN` remains in that script. The owner records fail-closed input tests as complete under T01. T02 is `wait`: provider-side invalidation and encrypted upload/restore receipts are absent. **Conclusion:** source removal is established in the checkout; predecessor invalidation is not. F-0010 stays open, low and embargoed. RPF-WP-0029-T02 names the remaining provider/recovery work. The 2026-09-15 embargo review/default stands. No inference is made about whether the predecessor is still valid. Only non-secret invalidation, governed ciphertext upload and restore receipts can complete the remaining evidence; source removal alone cannot lift the hold. ## Accepted retention obligation Read the existing acceptance and determination references in F-0008 and `audit-core/docs/erasure-and-audit.md`. Audit Core still documents the cleartext-hash confirmation problem and says keyed commitments are not built. No new answer to the co-residency horizon or keyed-commitment wait was present in the fetched risk-nexus inbox. This is not proof that no answer exists elsewhere. F-0008 already has a named accepter, an ending condition, a real determination and a next check. The reporting problem is classifying that accepted obligation as an untracked fix. The report should expose its existing acceptance terms without inventing engineering work or treating acceptance as closure. Its substantive review remains due: this sitting does not establish that the real-person/counterparty trigger has not fired and does not renew the legal basis. ## External intake and scheduled reviews Searched policy-nexus publication configuration, workplans and deployment files for a security contact/security.txt or delivered external-report route. None was found in those inspected sources. The existing intake proposal remains the available evidence; current public endpoints and estate-wide contact availability were not verified. Publishing a new contact requires its actual receiving owner. Searched activity-core's local definitions and evidence for the two risk register activities. No matching execution receipt was found in those paths. The two definitions in risk-nexus remain source instructions. Their live registration, execution and completed-session chain are unverified; this search is not proof that the activities do not run. No deployment or synchronization was attempted. ## Source provenance | Inspected source | SHA-256 of the non-secret document | | --- | --- | | qonto-assistant QONTO-WP-0005 | `f3b21ed7d046e7a4e5e8eee1397dcdcf1a17211f75786da3a0a2258b44802c3a` | | qonto-assistant cadence declaration | `69db6068b2e262f6b9108903cf7c5a7764efba5c981344c50df496018bc98ed9` | | qonto-assistant audit.py | `573e669914ae2ae77dfbf0a0929ef080cfbcb7dd4e0ba79e9408dd401fd74437` | | railiance-platform RPF-WP-0029 | `396d2e167b8bd1141671fadd864660a1e8bc6efb1ea3a09be3465e841ce33144` | | audit-core erasure-and-audit.md | `40d0f86ad401c3fb413fb21346a77210b6840d52f05093b31143a11b8a3a878b` | Observed HEADs: qonto `e5611147fd72a23e58618b87b0c3b96c807d0043`, railiance-platform `f637989a6911a7a13812cba223ffc007d78d6302`, audit-core `95dcb78e17d46889c17b55e3ba1aadbcceec6a99`, policy-nexus `c1b60f322e3bcddff3cece618ece2bd3686169e1`.