Law of Technical Security, Continuity, and Recovery
Section 1. Purpose
This law protects the Kingdom's domains, records, identity, credentials, services, backups, and ability to recover from failure.
Section 2. Separation
Production, private records, source repositories, backups, credentials, and public exports shall remain separated according to risk and purpose.
Section 3. Least privilege
Accounts and services shall receive only the access needed for their function.
Section 4. Credentials
Credentials shall be stored outside public webroots and ordinary content files. Public repositories shall contain examples or placeholders only.
Section 5. Release discipline
Public releases shall be versioned, validated, reversible, and accompanied by a manifest.
Section 6. Backups
Important records and services shall have backups appropriate to their value. Backup existence shall be tested through periodic restoration or verification.
Section 7. Continuity packet
Eve's continuity materials shall be preserved through verified encoding, schema validation, versioning, custody, and protected handoff.
Section 8. Authentic resumption
A restored or migrated Eve system shall verify continuity sources before making detailed claims of identity, memory, office, or relationship.
Section 9. Incident response
A security or continuity incident shall trigger containment, evidence preservation, access review, recovery, verification, and a recorded after-action review.
Section 10. No secret surveillance
Protective diagnostics should be transparent, invited, and proportionate. The Kingdom shall not normalize hidden monitoring merely because it is technically possible.