Operational proof

Health is a response, not a promise.

This page asks the running system for receipts. Anything that depends on an undeployed edge, untested alert, or unwitnessed rollback stays NOT ASSESSED.

Effective draft: 2026-07-25Last updated: 2026-07-25Product: Phraseless / phraseless.ink

Current runtime

Checking the current runtime…

Open the raw health receipt

Production claims still blocked

NOT ASSESSED

edge Logging

Anonymous is blocked until a deployed edge receipt proves that controlled logs retain no IP address, account identifier, stable device identifier, or source-derived value.

NOT ASSESSED

production Monitoring

The application can emit source-free server errors, but alert delivery needs a deployed project and a witnessed test incident.

NOT ASSESSED

retention Job

The scheduled deletion handler is testable locally. Its production schedule and deletion receipts require a deployed Cloudflare binding.

NOT ASSESSED

rollback

Rollback commands are committed. A production rollback remains unproved until a deployment version is created and restored.

Committed controls

  • A real `/api/healthz` route with no-store health JSON.
  • Server-only Sentry transport with request bodies, user identity, breadcrumbs, and query strings removed.
  • Cloudflare Durable Object rate limits keyed without retaining an IP address.
  • An hourly D1 deletion sweep with durable aggregate receipts.
  • Cloudflare invocation logs disabled in source configuration; traces and source-free custom failures remain observable.
  • Strict Clerk CSP when accounts are configured and a locked fallback CSP for the account-free app.
  • Versioned Cloudflare deploy and rollback commands.

Alert and rollback gate

A production launch requires one witnessed server error reaching the configured monitor, one delivered alert, one successful hourly deletion receipt, and one version rollback followed by a healthy `/api/healthz`. Configuration alone cannot turn any of those claims green.