{
  "schemaVersion": "gships-review-packet-1",
  "packetId": "tasks:disconnected-cyber-recovery",
  "stableId": "disconnected-cyber-recovery",
  "family": "tasks",
  "slug": "disconnected-cyber-recovery",
  "title": "Disconnected cyber recovery",
  "status": "prepared-human-review-not-started",
  "release": {
    "releaseId": "public-alpha-2026-07-26-research-visuals-r14",
    "sourceCommit": "3eb036fce3d711336c8c605625895e8a2e799ab0",
    "corpusGeneratedAt": "2026-07-25",
    "frozenAt": "2026-07-26T22:50:50.000Z",
    "canonicalOrigin": "https://gships.dammonburden.com"
  },
  "paths": {
    "human": "/review/tasks/disconnected-cyber-recovery",
    "family": "/review/tasks",
    "packet": "/review-packets/tasks/disconnected-cyber-recovery.5b38838781df84d3.json",
    "decisionTemplate": "/review-packets/tasks/disconnected-cyber-recovery.5b38838781df84d3.decision-template.json",
    "worksheet": "/review-packets/tasks/disconnected-cyber-recovery.5b38838781df84d3.worksheet.md",
    "byFingerprint": "/review-packets/by-fingerprint/5b38838781df84d3370a19e9584e93683429b9580b5b567ee09fc6df08fd7596.json"
  },
  "boundary": "Prepared review packet; human review has not started. This packet is not a completed review, endorsement, reviewer appointment, partnership, or authorization to act.",
  "governingPolicies": [
    {
      "id": "policy-editorial-governance-001",
      "version": "0.1.0",
      "path": "/editorial-policy",
      "recordType": "governing-policy",
      "fingerprint": "1f6a1f823e8bfe891b6a707c5dce2ee2337c0bb7d915b48d6060ca82b8da1b47",
      "snapshot": {
        "id": "policy-editorial-governance-001",
        "version": "0.1.0",
        "status": "foundation-policy-controls-not-yet-staffed",
        "adoptedForFoundation": "2026-07-25",
        "title": "Editorial governance and independent review",
        "publisher": "GShips Project",
        "maintainer": "Dammon Burden",
        "publisherInterest": "The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.",
        "currentBoundary": "No independent domain reviewer or review council is currently appointed. Foundation records and outlines may not be represented as independently reviewed.",
        "reviewerSelection": [
          "Publish the reviewer’s name, relevant credentials or lived expertise, review scope, compensation status, and declared conflicts with consent.",
          "Select for the actual claim domain rather than general prestige; include affected-community and disability-led expertise where rights or access are involved.",
          "Do not treat an employee, investor, customer, sponsor, source author, or directly supervised collaborator as independent for the affected claim."
        ],
        "reviewProcess": [
          "Provide the exact claim, sources, locators, assumptions, counterevidence, transfer limits, and proposed evidence dimensions.",
          "Record approve, revise, contest, or reject at claim level; silence and event attendance never count as review.",
          "Publish material minority findings and the editor’s reasoned response.",
          "High-consequence medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use claims require two qualified independent reviewers with complementary scopes.",
          "A reviewer may recuse at any time; unresolved conflicts or missing expertise block the reviewed label."
        ],
        "appealAndCorrection": [
          "A correction receives a reference identifier and triage record; safety-critical allegations receive priority.",
          "A material editorial decision may be appealed to a reviewer not involved in the original decision once such a panel exists.",
          "Substantive reversals, unresolved disputes, and removed conclusions receive a dated public record that protects reporter privacy.",
          "No sponsor, customer, founder, or reviewer may purchase, suppress, or unilaterally assign an evidence grade."
        ],
        "publicationGate": "Public 1.0 requires named review coverage across every Academy track, documented high-consequence two-person review, a material-corrections log, reviewer conflict records, and an operating appeal path.",
        "correctionPath": "/corrections"
      }
    },
    {
      "id": "policy-dual-use-001",
      "version": "0.1.0",
      "path": "/dual-use",
      "recordType": "governing-policy",
      "fingerprint": "81637e2849f9c0866d23f7174eb9a2ce522b86313167ebf5022fca122d6e506c",
      "snapshot": {
        "id": "policy-dual-use-001",
        "version": "0.1.0",
        "status": "planned-controls-not-yet-operational",
        "adoptedForFoundation": "2026-07-25",
        "title": "Civil, defensive, and rights-preserving use boundary",
        "summary": "GShips may research safety, resilience, logistics, communications, recovery, and cyber defense only within explicit end-use, rights, and independent-review controls. Calling an activity defensive is never sufficient by itself.",
        "scopeTrigger": "Apply dual-use review before accepting or materially advancing customer, funder, collaborator, operational, procurement, or publication-sensitive work whose capability, data, end use, or transfer could reasonably enable a prohibited use. Public non-actionable education still follows prohibited-content and sensitive-publication controls.",
        "allowedInPrinciple": [
          "Safety engineering and independently assessed protection",
          "Resilience, graceful degradation, recovery, and disaster response",
          "Civil logistics, maintenance, communications, and knowledge continuity",
          "Cyber defense, secure software, incident response, and recovery",
          "Rights-preserving health, accessibility, ecology, education, and governance research"
        ],
        "prohibited": [
          "Identification, tracking, prioritization, or engagement of people or assets for force, weapons, repression, or offensive operations; safety navigation, astronomy, collision avoidance, search and rescue, and independently governed planetary defense are not prohibited by this clause",
          "Weapons command-and-control or targeting support",
          "Offensive access, persistence, exploitation, or destructive cyber payloads",
          "Mass surveillance, biometric repression, or political-control systems",
          "Autonomous force application",
          "Coercive reproductive, medical, genetic, disability, or civic control",
          "Nonconsensual experimentation or treating residents as research instruments"
        ],
        "reviewRequiredBeforeAnyRelevantWork": [
          "Customer, funder, collaborator, jurisdiction, beneficial-owner, and end-use screening",
          "Export-control and sanctions review by qualified counsel when applicable",
          "Written scope, allowed-use, prohibited-use, audit, termination, and incident clauses",
          "Independent stop-work authority with a named alternate and founder recusal",
          "Sensitive-publication and information-hazard review",
          "Whistleblowing, escalation, incident response, appeal, and anti-retaliation paths",
          "Aggregate transparency reporting that protects legitimate privacy and security"
        ],
        "currentBoundary": "No screening body, independent stop-work authority, contractual controls, or appeal body currently exists. Therefore no relevant customer, defense, dual-use, or operational engagement is authorized by this policy.",
        "changeControl": "Material changes require a dated public rationale, independent review, and may not be approved by the founder alone.",
        "correctionPath": "/corrections"
      }
    }
  ],
  "reviewContract": {
    "questions": [
      {
        "id": "question-1",
        "text": "Is the task concrete, Earth-first, evidence-bearing, reversible, and bounded by explicit veto conditions?",
        "required": true
      },
      {
        "id": "question-2",
        "text": "Do every candidate tier, rationale, and next action remain specific to this task without becoming an entity ranking?",
        "required": true
      },
      {
        "id": "question-3",
        "text": "Would the proposed evidence artifact let an independent person falsify or stop the work?",
        "required": true
      }
    ],
    "exclusions": [
      "Task matches do not authorize outreach, registration, application, funding, procurement, or commitment.",
      "A candidate tier is not an organization, event, or opportunity quality score."
    ],
    "requestedScopeCodes": [
      "affected-public-rights",
      "ecosystem-due-diligence",
      "institution-building"
    ],
    "dispositions": [
      "approve",
      "revise",
      "contest",
      "reject",
      "recuse"
    ],
    "prohibitedInputs": [
      "private legal names or contact details",
      "identity documents or raw credential files",
      "accessibility or medical records",
      "confidential conflict evidence",
      "classified, export-controlled, proprietary, or exploit material"
    ],
    "freshness": {
      "maximumDecisionAgeFromFreezeDays": 90,
      "eventOccurrenceRule": "Not applicable to this packet family."
    },
    "completionRule": "Every primary record must receive the required number of valid, current-fingerprint approvals; every complementary scope group and required domain must be covered; any unresolved revise, contest, or reject disposition blocks publication.",
    "highConsequenceRule": "Named medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use conclusions require two distinct qualified independent humans covering complementary domain-method and rights/public-interest scopes."
  },
  "primaryRecords": [
    {
      "recordType": "ecosystem-task",
      "recordId": "disconnected-cyber-recovery",
      "title": "Disconnected cyber recovery",
      "publicPath": "/partners/tasks/disconnected-cyber-recovery",
      "recordFingerprint": "61f1d0643ce61c0454ee0edf1aee4169766c17e3738c3235d813e5191ac3cb18",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "affected-public-rights",
              "institution-building"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "disconnected-cyber-recovery",
        "slug": "disconnected-cyber-recovery",
        "title": "Disconnected cyber recovery",
        "publicQuestion": "Can a safety-critical habitat restore trusted software, procedures, keys, and configuration without cloud access or offensive capability?",
        "summary": "Threat-model and rehearse a strictly civil, defensive recovery path for disconnected infrastructure with deterministic safety boundaries.",
        "systemSlugs": [
          "power-thermal",
          "ai-autonomy",
          "cybersecurity",
          "communications-navigation"
        ],
        "institutionalRoles": [
          "applied-rd",
          "operator",
          "standards-assurance",
          "regulation-governance",
          "potential-customer"
        ],
        "preferredEngagementModes": [
          "public reference architecture",
          "synthetic incident exercise",
          "bounded recovery rehearsal"
        ],
        "requiredEvidence": [
          "Civil and defensive threat model",
          "Signed known-good recovery material",
          "Key custody, revocation, expiry, and anti-rollback",
          "AI-off recovery and independently tested safety interlocks"
        ],
        "leadershipPathwayIds": [
          "cyber-knowledge-resilience"
        ],
        "fitDimensionIds": [
          "task-fit",
          "evidence-relevance",
          "access-feasibility",
          "public-benefit-alignment",
          "independence",
          "rights-environmental-compatibility",
          "civil-defensive-compatibility",
          "failure-learning-value"
        ],
        "mandatoryVetoIds": [
          "relationship-accuracy",
          "civil-defensive-boundary",
          "rights-consent-accessibility",
          "clinical-biosafety-participant-protection",
          "environmental-planetary-protection",
          "information-security-export-sanctions",
          "editorial-independence-conflict",
          "legitimate-access-and-authority"
        ],
        "conflicts": "The task may inform a future assurance product; no security organization, customer, sponsor, or partner relationship exists.",
        "whatWouldChange": "A completed public recovery exercise, changed threat model, or evidence that the scenario risks offensive transfer would change or stop the task."
      }
    },
    {
      "recordType": "partner-task-match",
      "recordId": "match-disconnected-cyber-recovery-nist-nccoe",
      "title": "disconnected-cyber-recovery · entity-nist-nccoe",
      "publicPath": "/partners",
      "recordFingerprint": "9ad50af07dca08968dc4f8c71a872f6d91616a1b6d80a1413833e4808577aec3",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "ecosystem-due-diligence",
              "institution-building"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "match-disconnected-cyber-recovery-nist-nccoe",
        "taskId": "disconnected-cyber-recovery",
        "organizationId": "entity-nist-nccoe",
        "tier": "monitor",
        "priorityOrder": null,
        "dimensions": {
          "task-fit": "strong",
          "evidence-relevance": "strong",
          "access-feasibility": "supported",
          "public-benefit-alignment": "strong",
          "independence": "unknown",
          "rights-environmental-compatibility": "supported",
          "civil-defensive-compatibility": "supported",
          "failure-learning-value": "strong"
        },
        "vetoChecks": {
          "relationship-accuracy": "pass",
          "civil-defensive-boundary": "unknown",
          "rights-consent-accessibility": "unknown",
          "clinical-biosafety-participant-protection": "unknown",
          "environmental-planetary-protection": "unknown",
          "information-security-export-sanctions": "unknown",
          "editorial-independence-conflict": "unknown",
          "legitimate-access-and-authority": "unknown"
        },
        "rationale": "The public profile and collaboration opportunity support defensive reference-architecture relevance; no collaboration, endorsement, or project acceptance is implied.",
        "boundedNextAction": "Map the synthetic recovery scenario against published NCCoE and NIST guidance before considering a public community-of-interest route.",
        "relationshipState": "indexed only; no formal relationship",
        "actionStatus": "proposed; not undertaken"
      }
    },
    {
      "recordType": "partner-task-match",
      "recordId": "match-disconnected-cyber-recovery-space-isac",
      "title": "disconnected-cyber-recovery · entity-space-isac",
      "publicPath": "/partners",
      "recordFingerprint": "45299181c08e97ad02b2420ac126578d285ed139a52fd8fd052f78507d7df1f3",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "ecosystem-due-diligence",
              "institution-building"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "match-disconnected-cyber-recovery-space-isac",
        "taskId": "disconnected-cyber-recovery",
        "organizationId": "entity-space-isac",
        "tier": "monitor",
        "priorityOrder": null,
        "dimensions": {
          "task-fit": "supported",
          "evidence-relevance": "tentative",
          "access-feasibility": "tentative",
          "public-benefit-alignment": "supported",
          "independence": "unknown",
          "rights-environmental-compatibility": "unknown",
          "civil-defensive-compatibility": "unknown",
          "failure-learning-value": "supported"
        },
        "vetoChecks": {
          "relationship-accuracy": "pass",
          "civil-defensive-boundary": "unknown",
          "rights-consent-accessibility": "unknown",
          "clinical-biosafety-participant-protection": "unknown",
          "environmental-planetary-protection": "unknown",
          "information-security-export-sanctions": "unknown",
          "editorial-independence-conflict": "unknown",
          "legitimate-access-and-authority": "unknown"
        },
        "rationale": "The reviewed profile supports civil-space cybersecurity and information-sharing relevance, but membership, classification, independence, and exact civil scope require verification.",
        "boundedNextAction": "Use only public materials to clarify membership, classification, and civil-and-defensive participation boundaries.",
        "relationshipState": "indexed only; no formal relationship",
        "actionStatus": "proposed; not undertaken"
      }
    },
    {
      "recordType": "event-task-match",
      "recordId": "event-match-cyber-nist-2026",
      "title": "disconnected-cyber-recovery · event-nist-software-and-supply-chain-assurance-forum",
      "publicPath": "/partners",
      "recordFingerprint": "730ad9966b8963be4148073808ed18e4a3a90da29762b308a1c65d1f6e46d35e",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "ecosystem-due-diligence",
              "institution-building"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "event-match-cyber-nist-2026",
        "taskId": "disconnected-cyber-recovery",
        "eventId": "event-nist-software-and-supply-chain-assurance-forum",
        "tier": "monitor",
        "fitRationale": "Relevant to SBOMs, provenance, reproducible builds, and long-life supply-chain assurance.",
        "intendedArtifact": "A public defensive recovery requirements crosswalk; no implication of NIST approval.",
        "actionStatus": "proposed; not undertaken"
      }
    },
    {
      "recordType": "opportunity-task-match",
      "recordId": "opportunity-match-cyber-nccoe",
      "title": "disconnected-cyber-recovery · opp-nccoe",
      "publicPath": "/partners",
      "recordFingerprint": "2c93b3607e683586277f65e6bedbc5d49d0728493200be5df52754929feaa6b0",
      "reviewRequirements": {
        "minimumIndependentApprovals": 1,
        "highConsequenceDomains": [],
        "requiredDomainCodes": [],
        "requiredComplementaryScopeGroups": [
          {
            "id": "bounded-competence",
            "scopeClass": "bounded-competence",
            "oneOf": [
              "ecosystem-due-diligence",
              "institution-building"
            ]
          }
        ],
        "unresolvedNegativeFindingBlocksPublication": true
      },
      "referenceIds": [],
      "snapshot": {
        "id": "opportunity-match-cyber-nccoe",
        "taskId": "disconnected-cyber-recovery",
        "opportunityId": "opp-nccoe",
        "tier": "monitor",
        "fitRationale": "Project-specific public collaboration may fit a civil recovery use case; acceptance and independence are not implied.",
        "requiredArtifact": "A public defensive use case with no sensitive operational data.",
        "actionStatus": "proposed; not undertaken"
      }
    }
  ],
  "linkedRecords": [
    {
      "recordType": "ecosystem-organization",
      "recordId": "entity-nist-nccoe",
      "title": "NIST NCCoE",
      "publicPath": "/partners/nist-nccoe",
      "recordFingerprint": "52725a8f6cf64cd43eb01f07ed00804d3915f68bfe54580900bb287662d024eb"
    },
    {
      "recordType": "ecosystem-organization",
      "recordId": "entity-space-isac",
      "title": "Space Information Sharing and Analysis Center",
      "publicPath": "/partners/space-isac",
      "recordFingerprint": "9c660d3f9e3b54dc6e54bf6439c51c2d4a7b96116b679a75169f13531f36038a"
    },
    {
      "recordType": "event-occurrence",
      "recordId": "event-nist-software-and-supply-chain-assurance-forum",
      "title": "NIST Software and Supply Chain Assurance Forum",
      "publicPath": "/events/nist-software-and-supply-chain-assurance-forum",
      "recordFingerprint": "abeee8bf7a0996bd2f242a4c15ccfc9faa810c25c3e0fc5140179d8a5ffaac96"
    },
    {
      "recordType": "opportunity",
      "recordId": "opp-nccoe",
      "title": "NIST NCCoE collaboration",
      "publicPath": "/opportunities/opp-nccoe",
      "recordFingerprint": "89db2ec2f22a5eca848c6035b8c80d4807bc7c6ff4c6a0e6b7bac1a1c22367f8"
    }
  ],
  "referenceSnapshots": [],
  "packetFingerprint": "5b38838781df84d3370a19e9584e93683429b9580b5b567ee09fc6df08fd7596"
}
