Technical detail
Look under the surface only as far as you need
The technology matters because people rely on the result. Start with the boundary you care about—planning, access, recovery, privacy or evidence—and follow the detail only as far as it helps you understand or verify the system.
Complete MP-OPT ecosystem
Planning, authenticated access, public access, delivery, availability and evidence remain separate domains.
Desktop App
Local planning, optimisation, publishing and event-scoped processor signing
External recovery storage
Encrypted exported snapshots; private AGE identity stays with the operator
Self-hosted Server
Node A
Caddy, frontend, API and PostgreSQL
Node B (HA)
Verified peer recovery point and failover target
Cloudflare
DNS, load balancer and bounded witness
Evidence repository
Append-only public verification material
Browser and phone/PWA
Passkey-authenticated Masterplan or bearer Public Schedule
SMTP and Google Calendar
Optional controller-declared delivery and calendar providers
How optimisation helps
A non-technical explanation of hard rules, preferences and why human review remains important.
Read the overviewGDPR and FADP support
Controls and evidence MP-Opt provides, plus the decisions and responsibilities it cannot make for a controller.
Read the boundarySecurity and keys
Passkeys, signing roles, encryption, custody, recovery and the limits of each control.
Open the security mapDeletion and evidence
How Desktop, Server, backups and root confirmation contribute to a verifiable record.
Understand the evidenceTwo schedule audiences
The audience is fixed by the publication surface rather than selected field by field.
Public Schedule
Always public to anyone holding the intentionally published route or bearer link
Masterplan
Always restricted to authenticated people with an assigned event role
Security trust boundaries
Each boundary uses a different credential and limits what a compromise can reach.
Desktop workstation
Local project database, per-launch backend token, publish credentials in the OS secure store
User device
Passkey private key in the authenticator; session in a protected browser cookie
Public HTTPS boundary
Cloudflare and Caddy
Routing, TLS, headers, and request boundary
FastAPI
Passkeys, sessions, CSRF, roles, reauthentication, limits, and audit
PostgreSQL
Application data, public keys, hashed sessions, and hashed publish secrets
Protected service secrets
Docker secret files on the relevant VPS; node-local HA identities stay local
Operator recovery custody
Only the public age recipient is configured on servers; the private identity remains off-host
Keys are independently generated. Arrows show responsibility, never derivation.
Controller Ed25519
Controller trust and governance statements
Event processor Ed25519
Desktop policy, deletion and local-copy receipts
Root passkey
Human authorisation of privileged Server actions
Instance evidence key
Evidence-chain and final-receipt sealing
Verifiable evidence
Exact statements, signatures, digests and chain links—not proof of physical deletion outside controlled systems