Masterplan Optimiser

Technical detail

Look under the surface only as far as you need

The technology matters because people rely on the result. Start with the boundary you care about—planning, access, recovery, privacy or evidence—and follow the detail only as far as it helps you understand or verify the system.

Complete MP-OPT ecosystem

Planning, authenticated access, public access, delivery, availability and evidence remain separate domains.

Desktop App

Local planning, optimisation, publishing and event-scoped processor signing

External recovery storage

Encrypted exported snapshots; private AGE identity stays with the operator

Self-hosted Server

Node A

Caddy, frontend, API and PostgreSQL

Node B (HA)

Verified peer recovery point and failover target

Cloudflare

DNS, load balancer and bounded witness

Evidence repository

Append-only public verification material

Browser and phone/PWA

Passkey-authenticated Masterplan or bearer Public Schedule

SMTP and Google Calendar

Optional controller-declared delivery and calendar providers

How optimisation helps

A non-technical explanation of hard rules, preferences and why human review remains important.

Read the overview

GDPR and FADP support

Controls and evidence MP-Opt provides, plus the decisions and responsibilities it cannot make for a controller.

Read the boundary

Security and keys

Passkeys, signing roles, encryption, custody, recovery and the limits of each control.

Open the security map

Deletion and evidence

How Desktop, Server, backups and root confirmation contribute to a verifiable record.

Understand the evidence

Two schedule audiences

The audience is fixed by the publication surface rather than selected field by field.

Public Schedule

Always public to anyone holding the intentionally published route or bearer link

Masterplan

Always restricted to authenticated people with an assigned event role

Security trust boundaries

Each boundary uses a different credential and limits what a compromise can reach.

Desktop workstation

Local project database, per-launch backend token, publish credentials in the OS secure store

User device

Passkey private key in the authenticator; session in a protected browser cookie

Public HTTPS boundary

Cloudflare and Caddy

Routing, TLS, headers, and request boundary

FastAPI

Passkeys, sessions, CSRF, roles, reauthentication, limits, and audit

PostgreSQL

Application data, public keys, hashed sessions, and hashed publish secrets

Protected service secrets

Docker secret files on the relevant VPS; node-local HA identities stay local

Operator recovery custody

Only the public age recipient is configured on servers; the private identity remains off-host

Signing and authorisation map

Keys are independently generated. Arrows show responsibility, never derivation.

Controller Ed25519

Controller trust and governance statements

Event processor Ed25519

Desktop policy, deletion and local-copy receipts

Root passkey

Human authorisation of privileged Server actions

Instance evidence key

Evidence-chain and final-receipt sealing

Verifiable evidence

Exact statements, signatures, digests and chain links—not proof of physical deletion outside controlled systems

Canonical component references