Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Hardware, platform and safety

Security and privacy

Security and privacy themes in the Simca design: local-first data, no telemetry, roles, audit, backups. Design intent on

Status labels: Built in the repository (checked files or developer tooling, not an app feature) Designed in a document, no code yet Planned: listed in the catalog, not built Not decided Not in the catalog yet (a gap) No claim made

What goes wrong with “Local-first data” in a shop, in particular regarding lost device?

Designed C0176

Data lives on the shop's own devices by default; nothing requires a cloud account. This is a design principle in the README. Plan for: lost device; shared device; backup location. It is designed in a document and no code exists.

Open this answer on its own page

How risky is “No telemetry” to get wrong, especially around crash reports?

Designed C0177

The README states no telemetry or data collection. It is a principle, not a verified property of software that does not exist yet. Plan for: crash reports; update checks; optional features that need a network. It is designed in a document and no code exists.

Open this answer on its own page

Which edge cases come up around “Roles and permissions”, especially around shared logins?

Planned C0178

Giving cashiers, supervisors and owners different rights, and limiting risky actions. Plan for: shared logins; temporary permissions; owner lockout. In the catalog it is a plan and nothing is built.

Open this answer on its own page

What should I plan for with “Audit trail”, in particular regarding clock changes?

Planned C0179

An append-only record of edits, voids, discounts and logins. Plan for: clock changes; log size; deleting the log. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Is “Encryption at rest” supported today, considering key storage?

Not decided C0180

Protecting the database file on a lost device. Whether and how is part of the stack decision. Plan for: key storage; performance; recovery if a key is lost. It is not decided.

Open this answer on its own page

How does Simca approach “Backups”, with a focus on untested backups?

Planned C0181

Local backups to drives or another device, with restore tests. Plan for: untested backups; backup of a corrupt file; offsite copy. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Is “Restore” supported today, considering version mismatch?

Planned C0182

Rebuilding a device from a backup, checking integrity first. Plan for: version mismatch; partial restore; restoring over newer data. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Is “Device pairing” supported today, in particular regarding unknown device?

Planned C0183

Trusting a second device on the shop network. Plan for: unknown device; revoking a lost phone; time sync. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Where does “Signed files” fit in Simca, with a focus on key rotation?

Not decided C0184

Interchange documents are planned as signed files so they can be verified offline. Signature scheme is not decided. Plan for: key rotation; offline verification; revocation. It is not decided.

Open this answer on its own page

What goes wrong with “Data minimisation” in a shop, especially around customer id thresholds?

Planned C0185

Only collecting what the sale needs, with customers' details optional. Plan for: customer id thresholds; export requests; retention. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Where does “PINs and sessions” fit in Simca, in particular regarding shoulder surfing?

Planned C0186

Quick staff logins that time out safely. Plan for: shoulder surfing; shared pin; lock on idle. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Why does “Secure updates” matter for a small business, with a focus on failed update?

Planned C0187

Updating without a mandatory internet connection, with rollback. Plan for: failed update; offline update media; version skew in a shop. In the catalog it is a plan and nothing is built.

Open this answer on its own page

Why does “Software supply chain” matter for a small business, considering dependency vulnerabilities?

Designed C0188

Building and signing releases and checking dependencies. A process plan in the repo, not a result. Plan for: dependency vulnerabilities; reproducible builds; signing keys. It is designed in a document and no code exists.

Open this answer on its own page

What should owners check about “Threat model”, in particular regarding robbery?

Gap C0189

A written list of what the system defends against. Not yet written for the product. Plan for: robbery; insider theft; malware on pcs. It is a gap: the catalog does not cover it.

Open this answer on its own page