v4.0.1 - Retention Safety & Secrets at Rest

P0 follow-up to v4.0.0, opened after a real session's audio was destroyed with no recovery window. Raw audio must never be deleted inline: every deletion path goes through the trash with a minimum 7-day grace, whatever the retention mode. Plus three defects found while investigating that loss - a credential stored in plaintext at rest, backups written by a client the server cannot restore, and a database restore onto a host with a different SECRET_KEY silently destroying every encrypted setting. Overlaps v4.1.0 'Data Durability and Recovery' by design; these are the parts that cannot wait for it.

No due date
100% Completed