# REPORT — v0.289.0 / v0.289.1: the off-site key cannot delete (decisions 68–69) — 2026-10-03 Full session report: `felhom.eu/REPORT-offsite-lock-build-2026-10-03.md`. Architecture: `07-backup-architecture.md` (custody block, threat rows 9/10/12), `06` §3.6, `09` §3 decisions 68–70. - **v0.289.0:** append-only `rclone:` transport for the hub tier; the box sends only its public key to the hub registrar and proves the pin before configuring; both `forget` sites, the move-aside and the abandonment leave the box on that tier; retention only inside a hub window behind the fake-snapshot guard (R-822). - **v0.289.1 (found live):** the provider's rclone NOTICE broke every `--json` parse → the box recorded 0 snapshots as measured and the hub mailed a false `offsite_snapshots_dropped`. The notice is stripped; an unreadable count keeps the last value with `stats_known=false`. **Two releases this session — the second one fixes a defect the first put live; the one-release rule was broken on purpose and is named here.** - Tests + red-proofs: `felhom.eu/documentation/audits/offsite-lock-build-2026-10-03/partC/red-proofs-controller.txt`. - Live: demo-felhom 11→13 snapshots, demo-hp 91→100 (history kept); a delete from each box refused (403); restore of one file and `check` through the pinned key on each. Floor 0.289.1 served to both; golden 0.289.1 baked + vouched. - **MinAgent 0.131.0** (unchanged).