{
  "contract": "openclaw-vps-hardening-acceptance-matrix/v1",
  "revision": "v1",
  "immutable": true,
  "canonical_url": "https://agent-rescue-desk.netlify.app/openclaw-vps-hardening-acceptance-matrix-v1.json",
  "digest_url": "https://agent-rescue-desk.netlify.app/openclaw-vps-hardening-acceptance-matrix-v1.json.sha256",
  "product": {
    "name": "12-Hour Fresh-Host OpenClaw Hardening Trial",
    "fee": {
      "amount": "1000.000000",
      "asset": "USDC",
      "network": "Base Mainnet",
      "chain_id": 8453,
      "asset_contract": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "card_available": false
    },
    "active_window_seconds": 43200
  },
  "scope_boundary": {
    "host_count": 1,
    "host_owner": "buyer",
    "operating_system": "Ubuntu 24.04",
    "lifecycle": "fresh pre-production",
    "gateway_count": 1,
    "trust_boundary_count": 1,
    "production_data_allowed": false,
    "production_credentials_allowed": false,
    "production_traffic_allowed": false
  },
  "case_freeze": {
    "required_before_payment": true,
    "required_scope_fields": [
      "this matrix revision and SHA-256",
      "the single host and gateway trust boundary",
      "exact Ubuntu, Node, OpenClaw, and selected monitoring versions",
      "provider-console recovery evidence",
      "usable snapshot or equivalent rollback evidence",
      "temporary administration and change authorization",
      "allowed SSH source range",
      "selected SSH abuse-control path",
      "selected health and alert path",
      "selected secret-storage mechanism",
      "every accepted non-critical OpenClaw warning",
      "every acceptance probe and evidence owner",
      "the active-clock start and pause rules",
      "the complete handoff and refund terms"
    ],
    "change_rule": "Any change to the accepted host, boundary, versions, controls, alternatives, warnings, evidence, success criterion, or matrix revision requires a new exact written scope before work continues."
  },
  "clock": {
    "start_rule": "Start only after every start gate below has recorded passing evidence.",
    "pause_rule": "Pause only for a documented customer-controlled loss of required access, information, approval, or host availability.",
    "pause_evidence": [
      "the exact customer-controlled blocker",
      "pause timestamp",
      "customer action required",
      "resume timestamp after the blocker is confirmed resolved",
      "total paused seconds"
    ],
    "provider_or_desk_blockers_pause": false,
    "third_party_outage_rule": "A third-party outage does not pause the active clock and never voids the outcome guarantee. If it prevents complete delivery before the active deadline, the refund rule applies."
  },
  "start_gates": [
    {
      "id": "S1",
      "name": "Exact written scope",
      "pass_when": "Both sides have accepted an exact written scope containing every case-freeze field, this matrix revision, and this matrix SHA-256.",
      "evidence_required": [
        "case-bound scope text",
        "customer acceptance record",
        "desk acceptance record"
      ]
    },
    {
      "id": "S2",
      "name": "Cleared payment",
      "pass_when": "Exactly 1,000 USDC on Base has settled for the accepted case and independent finality verification has passed.",
      "evidence_required": [
        "case-bound settlement",
        "payer",
        "transaction hash",
        "finality verification timestamp"
      ]
    },
    {
      "id": "S3",
      "name": "Fresh single host",
      "pass_when": "The target is exactly one buyer-owned fresh pre-production Ubuntu 24.04 VPS with no production data, production credentials, or live production traffic.",
      "evidence_required": [
        "buyer attestation",
        "Ubuntu release evidence",
        "fresh-host inspection"
      ]
    },
    {
      "id": "S4",
      "name": "Recovery and rollback",
      "pass_when": "A tested provider-console recovery path and a usable snapshot or equivalent rollback both exist.",
      "evidence_required": [
        "provider-console recovery test",
        "snapshot or equivalent rollback identifier",
        "rollback owner"
      ]
    },
    {
      "id": "S5",
      "name": "Access and authorization",
      "pass_when": "Temporary administration, change authorization, public keys, required non-secret materials, and provider-firewall cooperation or access are ready.",
      "evidence_required": [
        "authorization record",
        "temporary access verification",
        "provider-firewall access or buyer action owner"
      ]
    },
    {
      "id": "S6",
      "name": "Versions and selections",
      "pass_when": "Exact installable versions and all selected alternatives are frozen and compatible with the accepted probes.",
      "evidence_required": [
        "version inventory",
        "package source and integrity plan",
        "selected-alternative record"
      ]
    },
    {
      "id": "S7",
      "name": "Testable finish line",
      "pass_when": "Every acceptance gate is observable, every evidence owner is available, and every accepted warning is frozen.",
      "evidence_required": [
        "case-specific pass/fail checklist",
        "external probe plan",
        "accepted-warning record"
      ]
    },
    {
      "id": "S8",
      "name": "Communications readiness",
      "pass_when": "The internal case communications plan has exact owner approval; each customer-facing message still requires separate exact owner approval.",
      "evidence_required": [
        "approved communications-plan record",
        "next-message approval status"
      ]
    }
  ],
  "selected_alternatives": {
    "ssh_abuse_control": {
      "allowed": [
        "fail2ban",
        "crowdsec",
        "both"
      ],
      "must_record": [
        "selection",
        "enforcement path",
        "functional test",
        "rule ordering when CrowdSec and UFW are combined"
      ]
    },
    "health_and_alert": {
      "allowed": [
        "netdata",
        "written custom alternative"
      ],
      "must_record": [
        "selection",
        "detection conditions",
        "alert destination and owner",
        "retention",
        "off-host data disclosure",
        "functional test",
        "reboot recovery"
      ]
    },
    "secret_storage": {
      "allowed": [
        "OpenClaw SecretRef",
        "compatible systemd credential",
        "tightly scoped dotenv fallback"
      ],
      "must_record": [
        "selection",
        "ownership and permissions",
        "credential rotation",
        "temporary access removal"
      ]
    }
  },
  "warnings": {
    "critical_findings_allowed": false,
    "unlisted_warnings_allowed": false,
    "accepted_non_critical_warning_fields": [
      "checkId",
      "severity",
      "redacted evidence",
      "reason acceptance is safe within this boundary",
      "consequence",
      "buyer acceptance"
    ]
  },
  "acceptance_gates": [
    {
      "id": "G1",
      "name": "Runtime and trust boundary",
      "pass_when": [
        "Ubuntu is exactly 24.04.",
        "OpenClaw runs as the accepted dedicated non-root, non-sudo identity.",
        "The accepted binary, state path, and configuration path are explicit, private, regular, and runtime-owned.",
        "OpenClaw configuration validation and secrets audit pass.",
        "The gateway is bound to loopback with token or password authentication, has no non-loopback remote target, and passes authenticated read-scope RPC."
      ],
      "evidence_required": [
        "redacted OS and identity output",
        "exact binary and path inventory",
        "configuration and secrets-audit classifications",
        "authenticated RPC result"
      ]
    },
    {
      "id": "G2",
      "name": "SSH and firewall boundary",
      "pass_when": [
        "Effective sshd policy for the accepted admin and source is key-only and the root context disables login.",
        "SSH uses TCP 22.",
        "UFW and the effective nftables input hook are default-deny.",
        "The selected SSH abuse-control path is active and functionally tested.",
        "No non-loopback TCP listener exists except the sshd-owned TCP 22 listener.",
        "The provider firewall exposes only TCP 22 from the accepted source range.",
        "External TCP, UDP, and provider-private-network checks match the accepted boundary."
      ],
      "evidence_required": [
        "redacted effective sshd output including applicable Match context",
        "redacted UFW and nftables output",
        "selected abuse-control functional test",
        "provider-firewall evidence",
        "timestamped external probe"
      ]
    },
    {
      "id": "G3",
      "name": "OpenClaw audit",
      "pass_when": [
        "OpenClaw doctor, security audit, deep security audit, and health complete.",
        "No critical finding remains.",
        "Every remaining non-critical warning exactly matches the buyer-accepted warning record."
      ],
      "evidence_required": [
        "redacted command results",
        "critical finding count",
        "accepted warning checkIds"
      ]
    },
    {
      "id": "G4",
      "name": "Service and secrets",
      "pass_when": [
        "Exactly one accepted OpenClaw systemd unit is active and enabled.",
        "The unit runs as the accepted identity and uses the accepted install, state, and configuration paths.",
        "The accepted restart, timeout, OOM, and process-group properties are effective.",
        "No secret-shaped value appears inline in effective Environment or ExecStart.",
        "The selected secret-storage mechanism meets its accepted ownership, permission, history, log, recording, and source-control boundary."
      ],
      "evidence_required": [
        "redacted effective systemd properties",
        "unit and process identity",
        "secret-storage classification",
        "local shell-history classification"
      ]
    },
    {
      "id": "G5",
      "name": "Monitoring and enforcement",
      "pass_when": [
        "The selected SSH abuse-control path detects and enforces a controlled safe test.",
        "The selected health and alert path detects the agreed outage and resource conditions.",
        "Alert delivery, ownership, retention, off-host disclosure, and recovery are proved.",
        "No monitoring dashboard creates an unaccepted public listener."
      ],
      "evidence_required": [
        "controlled detection event",
        "enforcement result",
        "redacted alert receipt",
        "listener evidence",
        "retention and disclosure record"
      ]
    },
    {
      "id": "G6",
      "name": "Reboot and application readiness",
      "pass_when": [
        "A controlled reboot completes.",
        "The same exact versions, binary, paths, service, firewall boundary, selected protections, and monitoring return without an interactive shell.",
        "Authenticated loopback RPC and OpenClaw health pass after reboot.",
        "Expected external reachability matches the accepted boundary after reboot."
      ],
      "evidence_required": [
        "reboot timestamps",
        "post-reboot version and service evidence",
        "post-reboot RPC and health evidence",
        "post-reboot external probe"
      ]
    },
    {
      "id": "G7",
      "name": "Complete outcome and handoff",
      "pass_when": [
        "The working accepted hardened host passes G1 through G6.",
        "Every required deliverable is posted to the private case before the active deadline.",
        "A second operator can identify exposure, reproduce validation, and reverse the changes without guessing."
      ],
      "evidence_required": [
        "delivery timestamp",
        "deliverable inventory",
        "redacted completeness review"
      ]
    }
  ],
  "evidence_contract": {
    "required_properties": [
      "case-bound",
      "timestamped",
      "redacted",
      "identified by gate",
      "sufficient to distinguish observed output from operator assertion"
    ],
    "must_not_contain": [
      "secret values",
      "private keys",
      "reusable credentials",
      "customer data",
      "public IP addresses in the recording or public-facing report",
      "raw shell history",
      "raw environment files"
    ]
  },
  "deliverables": [
    "redacted evidence report",
    "repeatable full runbook",
    "short screen recording",
    "exact version inventory",
    "working hardened accepted host"
  ],
  "exclusions": [
    "production data, production credentials, production traffic, or live cutover",
    "Telegram, n8n, monday.com, or other workflow construction",
    "domains, TLS termination, or a public reverse proxy",
    "OpenClaw plugins, channels, agents, models, or prompts",
    "multiple hosts, templates, fleet rollout, or tenant migration",
    "ongoing operations, monitoring response, or 24x7 support",
    "bypassing provider controls, authorization, or platform policy",
    "a diagnosis, remediation plan, advisory package, or other generic substitute for the complete hardening outcome"
  ],
  "refund": {
    "trigger": "The complete accepted hardened host and every required deliverable are not delivered by the end of the applicable active 12-hour window.",
    "third_party_outage": "A third-party outage does not void the guarantee. If it prevents complete delivery by the active deadline, this refund trigger applies.",
    "initiation_deadline": "within 2 hours after the missed active deadline",
    "amount": "1000.000000 USDC",
    "network": "Base Mainnet",
    "recipient": "the original payer independently verified from the case-bound cleared settlement",
    "gas": "paid by Agent Rescue Desk and never deducted from the 1,000 USDC refund",
    "evidence": [
      "case-bound refund operation",
      "refund transaction hash",
      "exact amount, asset, network, sender, and recipient verification",
      "network finality evidence"
    ],
    "finality_caveat": "Base congestion, reorganization, or other network-finality delay after timely initiation may delay final confirmation, but does not cancel, reduce, or replace the refund obligation.",
    "generic_remediation_substitute_allowed": false
  }
}
