TRUST THROUGH SPECIFIC EVIDENCE

What has been verified—and what has not.

SecureServe is Early Access software. This page documents concrete release checks and operational boundaries without claiming a certification or independent audit that has not occurred.

macOS package verification

The universal macOS 0.1.1 PKG is signed with Apple Developer ID identities, notarized by Apple, stapled, accepted by Gatekeeper, and tested through install and upgrade.

Linux release verification

Linux x86-64 and ARM64 archives have published SHA-256 values. Public downloads were retrieved again and compared with the release manifest.

Automated security checks

The source passed Go race tests, vet, Staticcheck, Gosec, and govulncheck at the recorded release checkpoint, with no reachable vulnerability reported by that toolchain.

Backup and restore drill

An encrypted off-host backup was restored in an isolated environment. Configuration, administrator authentication and MFA, state, TLS material, and the SFTP host key were checked before cleanup.

Payment and license flow

A controlled live subscription test covered checkout, webhook delivery, signed Pro license verification, cancellation, full refund, and post-cancellation entitlement removal.

Security-relevant product controls

Important limitations

SecureServe has not completed an independent security audit or penetration test and is not presented as compliance-certified software. The default first-run certificate is self-signed. A trusted certificate, carefully configured firewall or reverse proxy, tested backups, monitoring, and an independent review are required before production internet exposure.

Safe evaluation recommendation

  1. Verify the download checksum.
  2. Start in a controlled local or private network.
  3. Change the generated administrator password and enable MFA.
  4. Create a limited test user and use non-sensitive files.
  5. Back up both config.json and the complete data/ directory.