CARE4U SPONSOR COMPLIANCE — SELF-HOSTED EDITION 1.0

Start with INSTALL.html. It opens in any browser and covers Namecheap/cPanel,
subdomain, HTTPS, private folders, staff access, migration and daily backups.

RUNTIME
Node.js >=22.13; a current supported 24.x is recommended. Uses built-in HTTP,
crypto and SQLite modules. No production npm dependencies, API key, ChatGPT
account, external database or external authentication provider is required.
The archive includes the built React frontend and its editable source.

START
Set CARE4U_ORIGIN (exact HTTPS origin, no final slash), CARE4U_DATA_DIR (absolute
private folder outside web document roots and outside the app folder), and
CARE4U_SETUP_TOKEN (fresh random key, at least 32 chars, for first setup only).
Run node app.js, or configure cPanel startup file app.js with Production mode.
Create the first admin through the login screen, then remove the setup key.
The app refuses non-HTTPS origins except localhost/127.0.0.1 for local testing.
Hosting must enforce HTTPS at the proxy/web-server layer; do not expose the
Node listening port directly to the internet. Configure a subdomain root,
not a URL subdirectory. Do not enable shared response caching.

FILES
public/       Compiled browser assets, no employee data
server/       HTTP API, auth, permissions, validation and database setup
app.js        cPanel-compatible CommonJS entry point
frontend/     Editable TypeScript/React source, not needed on the web server
migration/    Confidential original worker register; local admin import only
 tools/       Full backup, restore and sole-admin password recovery scripts
 tests/       Integration test and optional browser test source

DATABASE AND STORAGE
SQLite WAL mode; prepared statements, transactional writes and audit entries.
Suitable for a small staff team on one hosting account with a local writable
filesystem. Do not put the database on a network-mounted/shared filesystem,
run multiple independently stored replicas, or treat local copies as synced.
New database/schema is created at startup, with blank organisation settings.
Data and documents persist outside the app folder, so code updates do not
replace them. Database version is 1; later schema changes require migrations.

AUTHENTICATION
Scrypt password hashes (N=32768, r=8, p=3, random per-password salt).
Random session tokens, hashes stored in DB, HttpOnly/Secure/SameSite cookies
in HTTPS mode, per-session CSRF token, exact Origin checks on POST, persistent
15-minute login rate windows by email and socket IP. Reverse-proxy deployments
may share a socket IP, so the IP limit is deliberately broader than per-email.
Inactive sessions expire after 30 minutes; absolute lifetime 8 hours.
No public account signup or email password-reset links. New/reset account
passwords must change before records can be accessed. Account/password/access
changes revoke sessions. Passwords and session tokens are never in audit data.
Admin can create/reset/disable accounts. Staff cannot change their own role.
No MFA is included. Access to the hosting account itself controls the app,
database and backups: protect hosting access and review authorised staff.

PERMISSIONS
Admin: all operations. Editor: worker/task updates, upload/review/download,
CSV export and read all records. Viewer: read/download and CSV exports only.
Only admin can edit licence settings, import or export the full JSON dataset,
or manage staff. All roles can see every worker and all audit entries.
Enforced in the backend, independently of the interface.

DOCUMENTS
Up to 10 MiB per file, stored by random UUID outside the public folder.
PDF/PNG/JPG/DOCX/XLSX/CSV/TXT only, basic file-signature checks where applicable.
Authenticated, audited downloads return attachment Content-Disposition.
Not an antivirus/content-disarm service; supply malware scanning operationally
if required. No delete UI is included. Define a retention/deletion workflow
with the system maintainer rather than retaining records indefinitely.

BACKUP / RESTORE
node tools/backup.mjs /absolute/private-data /absolute/private-backups
node tools/restore.mjs /absolute/snapshot /absolute/new-empty-private-data
The backup uses the SQLite online-backup API and copies only committed
referenced documents from that snapshot. Do not delete or mutate stored
blobs outside the app while backing up. Output includes SHA-256 checksums.
Restore checks hashes, database integrity, and deletes sessions/attempts.
Stop the app for cutover; switch data-directory environment variable and
restart. Do not restore over the running database. Daily cron scheduling,
monitoring, off-host encryption/copy and retention are the operator's job.
App JSON exports omit file bytes/accounts and are not full system backups.

SOLE-ADMIN RECOVERY (HOSTING ACCOUNT OWNER)
Activate the cPanel Node environment. Set CARE4U_DATA_DIR. Run:
node tools/reset-admin.mjs admin@example.com
This prints a one-time temporary password to your own terminal, invalidates
that admin's sessions, logs the recovery and requires a password change.
Do not put passwords in command arguments or share terminal transcripts.

MIGRATION
original-register.json: 145 source workers, 166 CoS history rows; historical
and current statuses are included, unverified, and not replaced with guesses.
No source evidence checklist entry is an actual uploaded document. Permission
expiry and right-to-work dates remain blank where not known.
The importer is admin-only and refuses to overwrite a nonempty workspace.
Latest exports from the earlier app can be imported if they contain no document
references. Existing evidence requires a separately planned migration of bytes,
links and review history, not dropping the metadata to bypass the guard.

UPDATES
Back up first. Stop app in cPanel, upload replacement app.js/server/public/tools
files outside public_html, keep CARE4U_DATA_DIR, restart, and perform a smoke
check. Keep a copy of the previous release and its matching database backup.
Never extract a replacement archive over the private data directory.
For source changes, enter frontend/, install its package.json dependencies,
run npm run check and npm run build. The output is ../public. No frontend
build is needed for the supplied release. Update dependency pins and rerun
checks when maintaining the app. Third-party licences are in THIRD_PARTY.txt.

LIMITS
No automatic legal assessment or rule updating, no SMS submission integration,
no email notification service, no offline synchronisation, no granular worker
visibility, no MFA, no app-managed encryption at rest, no independent security
assessment. Care4U's team must review current Home Office guidance and records.
Local automated checks do not verify your domain, cPanel/Passenger mapping,
SSL, backup schedule, hosting isolation, malware handling or real staff access.
