Release truth
Service status
This page separates implemented code from owner-controlled operating state. No external provider or deployment is labelled verified without owner readback.
| Capability | State | Evidence boundary |
|---|---|---|
| Release | CANDIDATE | External gate state: OWNER_OPERATING_GATES_OPEN |
| Deployment profile | demo | Runtime refuses profile-incompatible configuration |
| Owner activation | OWNER_ACTIVATION_REQUIRED | Production providers, domains, schedules, monitoring, and support remain owner-controlled |
| Encrypted form intake | IMPLEMENTED | Production provider readback remains a launch acceptance step |
| Opaque receipt readback | IMPLEMENTED | Returns state only; never form contents |
| Delivery retry worker | IMPLEMENTED | Owner schedule creation and execution remain acceptance steps |
| Renvoro Account identity and entitlement | IMPLEMENTED | Owner-controlled cross-host deployment and reconciliation remain acceptance steps |
| Email delivery | OWNER ACTIVATION | Real provider delivery remains NOT_TESTED |
| Billing | PLATFORM AUTHORITY | Owner Stripe test and production journeys remain acceptance steps |
| Backup and restore | OWNER ACTIVATION | Remote D1 export and restore remain NOT_TESTED |
Questions: support@demo.invalid