[Task] Select the first trusted Postbox encryption and hand-over policy profile #25

Open
opened 2026-07-28 23:01:06 +02:00 by zemion · 0 comments
Owner

Decisions required

Before Postbox claims end-to-end encryption or distributes historical key epochs, select and document:

  • history available to a new incumbent;
  • recovery/escrow authority and quorum;
  • ordinary key rewrap versus full ciphertext re-encryption triggers;
  • assurance/quorum for delegation, hand-over, emergency access, export, and destruction;
  • vacancy escalation without granting unrelated plaintext access;
  • external-recipient proof and token profile.

Constraint

The plaintext first slice may reserve compatible metadata and interfaces, but must not imply that expiry or revocation removes plaintext already fetched or exported.

## Decisions required Before Postbox claims end-to-end encryption or distributes historical key epochs, select and document: - history available to a new incumbent; - recovery/escrow authority and quorum; - ordinary key rewrap versus full ciphertext re-encryption triggers; - assurance/quorum for delegation, hand-over, emergency access, export, and destruction; - vacancy escalation without granting unrelated plaintext access; - external-recipient proof and token profile. ## Constraint The plaintext first slice may reserve compatible metadata and interfaces, but must not imply that expiry or revocation removes plaintext already fetched or exported.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: GovOPlaN/govoplan-postbox#25
No description provided.