These are decisions and gaps, stated with the same weight as the section above. Two of them are deliberate and will not change; three are simply not done.
The whole pod is not encrypted — by design
Per-file encryption is available and off by default. Encrypting everything is different, and it is a decision rather than a backlog item: it would break Web Access Control and interoperability with other Solid apps, which is the property this product exists to provide. Anything you have not explicitly encrypted is readable by us as the operator.
Links do not expire — by design
Web Access Control has no expiry primitive, so an expiring link would have to be faked in our application layer and would not hold against a client talking to the server directly. We would rather say access is until revoked than imply a timer that is not enforced.
No access audit log
Nothing records who read what, and no part of the product will tell you. Building it means server-side logging, a retention decision, and somewhere to read it. Not started.
No third-party security audit
No external firm has reviewed this. We have not engaged one, and there is no report to publish or summarise.
No conformance pass
The Solid Conformance Test Suite has not been run against the deployment. Until it passes, and until interop with a third-party Solid app is demonstrated, we claim compatibility rather than conformance.