# Odexa v1.2 RC1 — release record

21 September 2026. Edition `1.2.0-rc.1` is an implementation candidate for implementer evaluation. It is not a stable production standard, external certification or a claim of adoption. The final package inventory identifies its exact bytes; website deployment is checked separately after publication.

## Scope and identity

The [specification](../SPECIFICATION.md) and its selected normative modules define static policy, direct and delegated free exchange, optional fixed-quote verification, asset/source evidence, continuing storage, observation coverage and portable evidence. The [47-requirement register](REQUIREMENTS.json) and [evidence map](REQUIREMENT-EVIDENCE.md) retain their complete scope. No capability was removed for release packaging.

The edition label is `1.2.0-rc.1`; native policy is `1.2.0-draft.1`, current service/authority is `1.2.0-draft.3`, legacy service is `1.2.0-draft.2`, and the Python distribution is `0.0.0.dev3`. Signed wire values are unchanged. The direct free path requires no commercial account or payment service. Appointed providers can offer governance, measurement and optional payment services within explicit originator authority. Synthetic payment examples move no money.

## Review and evidence

The [integrated audit](RELEASE-AUDIT.md), [four-role dispositions](../reviews/INTEGRATED-DISPOSITIONS.md) and their follow-ups record the completed technical review and corrected findings. Retained results comprise 644 Python methods, 206 Node tests and 57 isolated installed-flow checks, plus structural schema checks. These overlap and are not a combined conformance score. The final packaging check compares unchanged implementation/schema bytes with the tested source; no new full-suite run is claimed for documentation-only release changes.

The [packaging record](../verification/packaging-checks.json) identifies the wheel with complete approved licence texts and 73 unchanged packaged implementation files. Source archives include the separate Node clients and evidence; the Python wheel does not include the whole source archive. Documentation uses CC BY 4.0 and implementation material Apache 2.0, subject to the [licensing notice](../LICENSE.md).

## Security intake and historical status

The owner confirmed receipt of mail addressed to `hello@odexa.org`, then explicitly confirmed responsibility for monitoring private security reports on 21 September 2026. [Security reporting and deployment limits](../SECURITY.md) provide the current instructions. No response-time commitment or external audit is implied.

Earlier dated workbench plans, review records and verification reports are retained as historical evidence. Their statements that integrated review, email verification or monitoring is pending describe those earlier checkpoints. This release record and the current security document supersede those operational status statements; they do not change any normative contract, signed evidence, result count or historical hash. The final inventory hashes actual packaged files and declares edited public evidence copies separately.

Both Odexa sites use separate properties and containers in the Odexa analytics accounts; the commercial application uses separate accounts. Consent and aggregate GA4 receipt were checked before release. Site deployment checks, downloadable-byte verification and the retained draft-2 rollback target are recorded outside the immutable package after deployment.
