Skip to main content
PALOPALO FRAMEWORK

Public delivery map | v2.7 developer preview

Nine gates between preview and production

17 September 2026: the experimental ANS bridge and the unreleased swarm snapshot have separate evidence. Shared budgets, dynamic membership and supported cancellation are demonstrated with one central authority. Review current status and limits.

The v2.7 production profile keeps the boundary executable: data fitness, disclosure receipts and continuous invalidation are implemented as prototypes, while the bundled SQLite and in-process runtime remains denied for production until identity, tenancy, persistence, keys, connectors, resilience and independent assurance are externally implemented and evidenced. This remains a planning surface - not an authoritative project tracker, certification or release commitment.

Conditional estimate

Controlled single tenantabout 14-20 weeks

Production candidate after the applicable gates and independent retest pass.

Managed multi-tenantabout 24-36 weeks

Production candidate / GA only after isolation, resilience and assurance evidence.

Planning assumption: one dedicated product owner, one platform lead, two backend engineers, one frontend engineer, one DevSecOps engineer and fractional security/cryptography support. Ranges are directional, overlap by design and are not release commitments.

Five overlapping waves

Filter, inspect and export a local planning snapshot

Browser-local only: checklist state is saved on this device for planning convenience. It is never submitted and is not evidence of implementation or approval.

Wave 1 | Weeks 1-4Identity & BFF
Wave 2 | Weeks 3-8Keys & durable data
Wave 3 | Weeks 7-12Connectors & policy
Wave 4 | Weeks 11-16Tenancy & resilience
Wave 5 | Weeks 15-20Independent assurance
01

Wave 1 | Platform | In progress

Workload identity and scoped authorization

Replace shared bearer tokens with workload identity, OIDC/OAuth and scoped principal/tenant RBAC.

Acceptance criteria
  • Every machine and human request resolves to a verifiable principal and tenant.
  • Scopes are deny-by-default and enforced server-side.
  • Token rotation, revocation and negative authorization tests pass.
02

Wave 1 | Product / Platform | Planned

Same-origin Governance Hub BFF

Put the Hub behind a same-origin backend-for-frontend with authenticated executive, reviewer and operator sessions.

Acceptance criteria
  • No browser-held privileged runtime credential.
  • Role and tenant checks occur on every protected operation.
  • Session expiry, CSRF and privilege-escalation tests pass.
03

Wave 2 | Security | Planned

KMS/HSM-backed key custody

Move secrets and signing keys to managed custody with rotation, revocation and separation of duties.

Acceptance criteria
  • Application processes cannot export signing key material.
  • Rotation and emergency revocation are rehearsed.
  • Administrative and signing duties are separated and audited.
04

Wave 2 | Platform | Planned

Durable, coordinated data plane

Replace SQLite and in-process recovery with PostgreSQL, a durable queue/outbox, multi-replica coordination, backup and tested restore.

Acceptance criteria
  • Transactional outbox and idempotent consumers survive process loss.
  • Replica concurrency and lease recovery tests pass.
  • Encrypted backups meet documented RPO/RTO and restore is demonstrated.
05

Wave 3 | DevSecOps | Planned

Isolated and attested connectors

Isolate and attest connector workloads, enforce egress policy and remove alternate privileged execution paths.

Acceptance criteria
  • Protected credentials are available only to the governed connector.
  • Egress destinations and operations are allowlisted.
  • Bypass and compromised-connector scenarios are tested.
06

Wave 3 | Security | Planned

Authenticated policy distribution

Verify policy and bundle provenance; authenticate distribution and use mTLS where the threat model requires it.

Acceptance criteria
  • Only authorized publishers can promote versioned bundles.
  • Runtime verifies provenance and rejects stale, unsigned or invalid bundles.
  • Rollback and emergency policy procedures are audited.
07

Wave 4 | Security / Platform | Planned

Tenant isolation and operational resilience

Add tenant-isolation, abuse/rate-limit, audit-retention and disaster-recovery tests.

Acceptance criteria
  • Cross-tenant reads, writes and inference paths are denied under adversarial tests.
  • Rate limits and abuse controls fail safely.
  • Retention, deletion and disaster recovery meet approved policy.
08

Wave 4 | Product / Platform | Planned

Fresh n8n package 0.2 validation

Validate package 0.2 on fresh supported n8n canvases and real reversible connectors before npm or template submission.

Acceptance criteria
  • Clean installation and upgrade paths pass on declared n8n versions.
  • Allowed, denied, review, failure and verification branches pass with reversible tools.
  • Package provenance and documentation are independently reproducible.
09

Wave 5 | Independent assurance | Planned

Independent cyber and cryptographic assurance

Commission threat modelling, application/API penetration testing, cryptographic design review and container/supply-chain assessment.

Acceptance criteria
  • Independent reports define scope, methods, severity and reproducible findings.
  • Critical and high findings are remediated and retested.
  • Residual risk is explicitly accepted by accountable owners.

No gates match these filters.