Fail-closed checklist
Human evidence required before an operator checkpoint
Qualified German/EU legal reviewHuman review required · owner: qualified legal reviewer
Independent security review and threat-model outcomeHuman review required · owner: security reviewer
DPIA screening decision and, if required, approved DPIAHuman review required · owner: qualified legal reviewer
Final data inventory, purpose matrix and processor registerHuman review required · owner: compliance reviewer
Reviewed privacy, consent and retention materialsHuman review required · owner: qualified legal reviewer
Staging evidence for access, deletion, withdrawal and retentionHuman review required · owner: security reviewer
Independently verified rollback evidenceHuman review required · owner: security reviewer
Independent second human approvalHuman review required · owner: restricted administrator
P5 technical controls
Request surface prepared, activation still blocked
Response protectionCSP, frame denial, MIME protection, capability policy and no-store APIs
State-changing requestsTrusted same origin, Fetch Metadata, JSON marker and an 8 KiB decoded limit
Rate limitsBounded policies; missing durable store or opaque server scope fails closed
Hosted proofIndependent review and staging tests are still required before activation
The transfer feature remains hard-coded off and cannot be enabled through runtime configuration.
Qualified reviewers must provide evidence. The application cannot issue legal or security approval.
Even complete evidence only reaches a new explicit operator activation checkpoint.