The Levy Core On-Prem documentation and delivery model completed independent cross-model review covering the product architecture, engineering contract, release package, third-party installation procedure, clean-room certification protocol, and end-to-end traceability.
The review evaluated whether a qualified third party could install the complete application on customer-owned infrastructure without access to Levy's repositories or original server source, while preserving data residency, operational safety, financial integrity, evidence integrity, and customer control.
Review scope
The independent review covered these public contracts:
- Platform Architecture and Capabilities;
- Engineering and Release Reference;
- Release, Site, Configuration, and Evidence Contract;
- Third-Party Installation Guide;
- Independent Installation Certification;
- the package, installation, certification, and acceptance links between them.
Assurance areas
Product completeness
The review traced the rider, operator, rental, vehicle, pricing, zone, wallet, payment, messaging, identity, IoT, GPS, storage, scheduled-job, reporting, backup, recovery, and support capabilities from architecture through packaged artifacts, installer actions, verification evidence, and final acceptance.
Local operation and data residency
The review confirmed that the production profile removes mandatory hosted Supabase, Vercel, Stripe, Twilio, Levy CRM, cloud monitoring, and Levy-operated runtime dependencies. Customer data, telemetry, logs, metrics, traces, objects, evidence, and backups stay within the signed customer boundary. Optional support AI remains separately isolated and controlled by an explicit egress policy.
Source-confidential installation
The review examined the separation between customer custodians, the installation controller, and the third-party installer. The final contract gives the installer a signed client and bounded controller identity without Kubernetes, registry, database, object-store, secret, node, shell, image-export, raw-log, or generic workload access.
It also verifies source-exclusion scans, minimal runtime images, immutable digest-pinned artifact custody, signed target policy, schema-bound requests, allowlisted controller verbs, typed redacted receipts, and exhaustive negative tests.
Authentication and authorization
The review validated the complete request envelope, immutable controller-created case identifiers, customer and environment binding, nonce and idempotency controls, approval references, detached signatures, request expiry, protocol compatibility, rate limits, concurrency rules, access revocation, and cross-environment denial behavior.
Release and supply-chain integrity
The review covered package signing, canonicalization, trust anchors, key transition, revocation, entitlement, SBOM, provenance, vulnerability receipts, license notices, compatibility matrices, offline encrypted media, private-registry import, custody evidence, and deterministic package validation.
Installation safety
The ordered installation path was reviewed from customer readiness and trusted-tool bootstrap through artifact custody, infrastructure preflight, configuration approval, recovery-point creation, deployment, provider and IoT conformance, backup/restore, security and residency testing, golden journeys, controlled rollout, test-data disposition, and operational handoff.
Money and mobility invariants
The review verified that payment and wallet operations are idempotent and reconcilable and that retries, timeouts, duplicate webhooks, captures, voids, refunds, settlement, and provider outages have deterministic behavior. It also verified that dependency or entitlement failure cannot prevent an active rider from ending a ride or the platform from completing required lock and reconciliation actions.
Recovery and operational ownership
The review covered clean install, N-1 upgrade where applicable, rollback, forward recovery, isolated restore, disaster recovery, certificate and key rotation, capacity monitoring, provider outages, IoT failover, support bundles, temporary support access, uninstall, data disposition, and final revocation of installer access.
Independent installability
The certification protocol requires two consecutive clean-room installations by independent teams using the same package and access a real third party receives. One run exercises online customer-custodian delivery and the other exercises offline encrypted media. Undocumented assistance, missing artifacts, unsafe ambiguity, or privileged access invalidates the run.
Incorporated review outcomes
The final documentation incorporates every accepted blocker, high-priority, medium-priority, and smaller-gap finding from the independent review. The incorporated controls include:
- independently provisioned and verified installer tooling;
- customer-owned trust anchors and signed bootstrap evidence;
- immutable controller-created installation case IDs;
- full signed request-envelope coverage rather than partial-field signatures;
- explicit controller bootstrap, upgrade, rollback, and stored-version lifecycle;
- exact release, API, schema, platform, cryptographic-profile, and machine-contract binding;
- certification receipts with scope vectors for greenfield, offline, restore, rollback, adversarial denial, and handoff;
- package-class separation between lab certification candidates and production customer handoffs;
- clear classification of local CLI operations versus controller API operations;
- bounded evidence-writing endpoints and fixture-disposition approvals;
- complete Kubernetes denial and controller API negative-test matrices;
- independent offline-custody and revocation validation;
- verified access, media, cache, and workspace closure at handoff.
Assurance conclusion
The reviewed documentation forms one consistent production contract. Product capabilities map to owned components; components map to signed package artifacts; package artifacts map to installer phases; installer phases map to machine-generated evidence; and evidence maps to independent certification and customer acceptance.
The resulting handoff is complete, locally operable, source-confidential for the installer role, independently certifiable, and suitable for deployment by a qualified third party on customer-controlled infrastructure.