Operators

Participant state

Set AE_PARTICIPANT_DATA_DIR and a base64url-encoded 32-byte AE_PARTICIPANT_STATE_KEY. Each participant keeps an encrypted SQLite identity and independently verifiable envelope evidence. Never expose the key to a browser or commit it.

Observer hosting

The observer exposes sanitized read-only snapshots, journals, replay, and SSE. Loopback operation may launch fixed demo commands; non-loopback deployments disable process controls. Observer state is always removable presentation, not marketplace authority.

Recovery and evidence

Waku Store recovery is bounded and best-effort. Preserve run reports, NDJSON observer journals, proof bundles, and participant backups. A Light Push acknowledgement is not recipient delivery proof.