AutoCore Legal Readiness and Security Checklist
A source-based readiness checklist for legal identity, policy publication, and public verification.
Use this checklist before enabling a public legal surface. A green checklist means the documented controls were verified for the release candidate; it does not represent legal approval.
Release candidate source
This article reflects the audited AutoCore source revision 7a504f6e430c16d4fcb03ebdea3cc3fb7816df60 and immutable release-candidate tag v1.0.0-rc.1 at 9edfb109f44cc80385784c694b96392cfc04e70f. Configuration and external provider behavior remain deployment-dependent.
Source boundary
| Control | Source-verified behavior |
|---|---|
| Identity | Legal profile is complete, scoped to the intended installation, and reviewed by the accountable operator. |
| Content | Each required policy type has approved locale content with no placeholder text. |
| Publication | Publication is permission-gated, audited, checksum-bearing, and verified through the public route. |
| Recovery | Prior revisions and publication evidence are retained according to the operator's approved policy. |
High-risk operation
Use explicit authorization, a written reason, a confirmation gate, and post-action verification. Documentation does not grant permission to change a deployment.
Operational controls
Use the smallest verified control for the task. Keep provider, host, legal, and operator responsibilities separate from application behavior. When a control is not implemented or not verified, leave it disabled or mark it as a limitation.
Result format
For each item, record pass, fail, or not_applicable, the evidence reference, the reviewer, and the next action. Do not paste credentials or raw provider payloads into the record.
Verification
Verify the route, relevant API or configuration state, negative path, audit/evidence result, and public effect before closing the task. Record unknown or configuration-dependent behavior as a limitation.