# Monical's Public Source Protection Audit

Generated: 2026-08-10T07:16:51.660Z
Sales page: https://www.apps.betteritgroup.com/monicals

## Buyer-Safe Verdict

The public review site is designed to prove the workflow and buying paths without serving readable source, raw business exports, generated packets, credentials, or real license records.

## Current Build Boundary

- Backend build hash: 4f55575bfa2e
- Public source pipeline: public-source
- Public source fingerprint: 4fd49505b027 (46 normalized files)
- Built at: 2026-07-22T13:40:48.138Z
- Browser delivery: minified_content_hashed_assets
- Source delivery: readable_source_not_in_public_build
- app_js: 8f3de4087bbd
- styles_css: 69593fa08618
- admin_js: 154ebecf075a
- dough_js: 114099b93bc7
- dough_reference_js: b9d11bdd9845
- invite_js: bee8fd339199
- monicals_css: a9b27846e4b3
- monicals_js: a5f2bff3a288

## Browser Delivery Manifest

- Server logic boundary: PDF generation, FoodTec mapping, dough math seeds, sales licensing, payment fulfillment, audit records, and source-package building stay server-side.
- Review note: The browser bundle is a review and runtime surface, not the readable source handoff.

Asset guards:
- JavaScript is minified and mangled with Terser.
- CSS is minified with CleanCSS.
- HTML is minified with html-minifier-terser.
- Browser asset URLs use content hashes from built files.
- Top-level browser bundles are served through the server-controlled runtime asset route.
- Source maps are not emitted.

Blocked public material declared by build:
- public-source/
- server.js
- scripts/
- tests/
- lib/
- data/
- outputs/
- dist/
- node_modules/
- package manifests
- source maps
- environment files
- raw FoodTec exports
- generated PDFs
- license records
- audit records

## Publicly Allowed Review Surface

- The /monicals sales page.
- The guided demo shell using bundled sample data.
- Buyer-safe markdown packets for decision review, live proof, corporate evaluation, pilot approval value, payment-to-key flow, payment activation proof, sample term sheet, license handoff preview, and source handoff preview.
- Public health/build metadata needed to verify the served browser bundles.

## Private Or Blocked Material

- Readable source tree and server implementation files.
- Raw PDF templates and generated inventory or food-cost packets.
- Raw FoodTec exports, fixture exports, local data folders, and output folders.
- Buyer records, admin records, license records, audit logs, and source handoff packages.
- Source maps, package manifests, scripts, tests, and deployment archives.

## Verification Expectations

- Public source and private-data path checks must return not found with no-store caching and noindex/noarchive indexing headers.
- Public browser assets must be minified and content-hashed.
- Checkout must stay in request-review mode until payment, webhook fulfillment, buyer handoff, hosted sessions, and manual launch approval pass together.
- Full readable source is delivered only through the source-purchase handoff after signed approval/payment and authority verification.

## What This Audit Does Not Include

- No credential values.
- No real license keys.
- No buyer records or admin records.
- No readable source files or source archives.
- No generated PDFs, raw FoodTec exports, or private packet downloads.