Skip to content

fix(trust): database and backups are now encrypted at rest - #33

Merged
rclanan merged 1 commit into
mainfrom
fix/trust-db-encrypted-at-rest
Oct 4, 2026
Merged

rclanan merged 1 commit into
mainfrom
fix/trust-db-encrypted-at-rest

Conversation

@rclanan

@rclanan rclanan commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Postgres data on the production host is on a LUKS2 (aes-xts-plain64) volume since 2026-10-04; database backups are client-side encrypted (WAL-G libsodium, age) since 2026-10-03, restore drill passed. Updates the Encryption card, at-a-glance line, In-place list and meta description. Matches Privacy/DPA v2.3 (mockforge#1148). Build + internal link check pass.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Postgres data moved onto a LUKS2 (AES-XTS) volume on 2026-10-04 and backups
are client-side encrypted since 2026-10-03.
@codedig-ai

codedig-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

🟢 CodeDig PR Analysis — Low Risk (Score: 100/100)

Summary

Metric Value
Files Changed 0
Total Findings 0
Critical 0
High 0
Public API Changes 0
New PII Flows 0
Complexity Spikes 0
Co-change Risks 0

Risk Budget: 0/100 consumed (green status)

| Coverage data | not available |

🧪 Test Coverage Delta (no data)

Coverage data not available for this repo — enable via Settings → Coverage

→ View full report


Powered by CodeDig

@codedig-ai

codedig-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

🟢 CodeDig PR Analysis — Low Risk (Score: 100/100)

Summary

Metric Value
Files Changed 0
Total Findings 0
Critical 0
High 0
Public API Changes 0
New PII Flows 0
Complexity Spikes 0
Co-change Risks 0

Risk Budget: 0/100 consumed (green status)

| Coverage data | not available |

🧪 Test Coverage Delta (no data)

Coverage data not available for this repo — enable via Settings → Coverage

→ View full report


Powered by CodeDig

@codedig-ai codedig-ai Bot added codedig/blast-low Blast radius low — ≤ 10 callers affected codedig/effort-1 Effort score 1/5 — minimal blast radius and complexity codedig/risk-green Risk budget < 50 % — safe to merge labels Oct 4, 2026
@rclanan
rclanan merged commit 4edc289 into main Oct 4, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codedig/blast-low Blast radius low — ≤ 10 callers affected codedig/effort-1 Effort score 1/5 — minimal blast radius and complexity codedig/risk-green Risk budget < 50 % — safe to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant