Guard v1 release channel

Checkout opens only after the evidence does.

No production Guard artifact or purchase link is published until every owner-verifiable technical, merchant, legal, and retirement gate is backed by signed evidence.

Current status: withdrawn. The TinyZKP Guard subscription is no longer offered for purchase at any price. The MIT Community engine and the free resource estimator remain available; release.json is authoritative for engine release state.

Launch gates

Engine release ready

Official verifier checks, deterministic proof identity, both resource targets, fixed-host matrix, recovery and ENOSPC, fuzzing, provenance, SBOM, signatures, CLI behavior, OCI behavior, and immutable release identity.

Guard release ready

Foreground supervision, framing, signal/orphan safety, atomic state, canonical doctor-plan consumption, redacted diagnostics, exact-release resume, offline activation, OCI hardening, CI policy, signed channel/index, and package identity parity.

Exact Guard artifact published

The reviewed signed draft, OCI manifest, channel, release index, schemas, provenance, and public site identity must be published without rebuilding. During no-rebuild promotion this is the final publication gate; checkout remains controlled by the signed launch and commerce state.

Merchant sandbox lifecycle

Monthly, annual, decline, renewal, failed renewal/dunning, expiry, portal, cancellation, resumption, and refund pass against exact test IDs.

Live owner smoke

The owner verifies active monthly and annual variants, exact live prices, checkout rendering, generic portal configuration, and subscription license-key settings against the exact live IDs. No recurring self-purchase is required.

Legacy obligations resolved

No unresolved customer obligation remains and required financial records are retained.

Hosted infrastructure decommissioned

Legacy writes, jobs, and credentials are disabled, required records are retained, and all three retired hosts return static 410 responses with noindex. The 90-day observation period is post-launch monitoring.

Release rehearsal validated

The exact build, deployment, artifact identity, and rollback path pass a technical rehearsal for the applicable change class.

Transparent advisory metrics

Independent reproduction, specialist review, implementation review, one design-partner integration, three external workloads, two standard annual customers, and five unaided installs are published as advisory_status. They are currently not_completed and do not authorize or block owner-attested checkout.

Release identity

A qualified release binds the Guard version, exact engine source SHA, OCI digest, artifact hashes, schema versions, compatibility profile, release date, SBOM, provenance, signatures, benchmark evidence, and review evidence in one signed channel manifest.

ArtifactCurrent public availability
MIT Community sourceAvailable in the public repository
Qualified Community engine binary and OCI imageAwaiting engine release gates
Guard binary and OCI imageAwaiting all launch gates
Guard channel manifest and signed release indexPublished with the first qualified release
Guard checkoutWithdrawn, no longer sold

Customer delivery

Guard delivery is not published. This section becomes an exact download, checksum, signature, extract, and activation path only after signed artifact publication.

Update policy

TinyZKP schedules four qualification windows per year. A window publishes a new binary only when a warranted change passes its applicable automated technical gates; no quarterly binary is promised. Old immutable releases are retained because checkpoints are exact-release-bound. A compatibility profile expands only after its complete correctness, resource, recovery, provenance, signature, CLI, and OCI qualification is repeated.

No silent activation

The website cannot enable checkout by changing a button or adding a URL. The published commerce configuration must indicate a passed canonical launch gate and contain a separately reviewed hosted-checkout variant before page code makes a purchase control clickable.

Release-index state is not a remote kill switch

Superseded and withdrawn releases leave ordinary distribution, recommendation, or support as the index declares. An already-downloaded activated copy makes no channel request, cannot learn either state, and remains locally usable; this is not a technical resume-only restriction. An already-downloaded unactivated copy may still activate while Lemon Squeezy reports an active subscription because TinyZKP v1 has no release-specific denylist service.