Masterplan Optimiser

General audience

Understand the whole system before choosing a guide

MP-OPT separates local planning, deliberate publication, authenticated access, public schedules, infrastructure recovery and verifiable evidence. Each deployment declares its own controller, providers, countries, features and retention.

Complete MP-OPT ecosystem

Planning, authenticated access, public access, delivery, availability and evidence remain separate domains.

Desktop App

Local planning, optimisation, publishing and event-scoped processor signing

External recovery storage

Encrypted exported snapshots; private AGE identity stays with the operator

Self-hosted Server

Node A

Caddy, frontend, API and PostgreSQL

Node B (HA)

Verified peer recovery point and failover target

Cloudflare

DNS, load balancer and bounded witness

Evidence repository

Append-only public verification material

Browser and phone/PWA

Passkey-authenticated Masterplan or bearer Public Schedule

SMTP and Google Calendar

Optional controller-declared delivery and calendar providers

Audience and role boundaries

A role grants a bounded capability; root is a technical role and is not automatically the legal controller.

Participant

Views authenticated schedules and manages their own passkeys

Issuer / admin

Issues access and manages assigned events within policy

Root

Authorises privileged Server actions and final deletion closure

Controller

Declares purposes, providers, retention and governance facts

Two schedule audiences

The audience is fixed by the publication surface rather than selected field by field.

Public Schedule

Always public to anyone holding the intentionally published route or bearer link

Masterplan

Always restricted to authenticated people with an assigned event role

GDPR and Swiss FADP support

MP-OPT provides data-minimisation boundaries, deployment-specific notices, retention and erasure workflows, security controls and signed accountability evidence. The controller still decides applicability, purpose, legal basis, providers, transfers and organisational measures.

Read the data-protection overview

Canonical product documentation

This site explains the whole system by audience. Product-specific procedures remain canonical on the App, Server and Evidence-Public Pages sites.

What the evidence can—and cannot—prove

Signatures prove who signed an exact statement, whether records changed, and whether the required chain is complete. They do not prove physical deletion from undeclared devices, providers or copies outside the signer's controlled systems.

Read the security and key map