Access layer
Everyday, protected, and secondary access are intended to expose distinct sets of information.
This conceptual architecture records the current design direction: local critical paths, separate access states, narrow backend responsibility, and explicit recovery tradeoffs.
Protected operations are intended to happen locally. Network features should remain outside the critical path and receive only the minimum information their function requires.
No reverse controlThe service-side model contains no key or decrypt action.
Optional context is intended to be evaluated locally rather than becoming a service-side activity record.
Conceptual architecture · mobile product in developmentEveryday, protected, and secondary access are intended to expose distinct sets of information.
Protected content is planned to use local encryption and platform-supported key protection. Specific algorithms remain design targets until implementation evidence exists.
Prepared actions and optional context rules are intended to change state on the device.
Accounts, subscriptions, and optional encrypted backup are intended to remain separate from readable protected content.
If the company can always recover a key, the company may also become a path to protected content. The final recovery model must make that tradeoff explicit.
Context-aware behavior is useful only if it does not create a new record of sensitive location or behavior. Local evaluation is the design target.
Prepared state changes must feel immediate, but no numeric performance claim will be published until supported-device testing exists.