SARVALEKHA — EVALUATION PREPARATION Use this checklist to prepare a scoped technical discussion. This file does not submit a request or establish evaluation terms. Application / component: Technical owner: Operating system and architecture: Compiler, standard library, and build system: C++ language mode: Current event, logging, tracing, or analytics workflow: Primary use case (tracing, diagnostics, crash analysis, UI profiling, analytics, or logging): Trace propagation, W3C interoperability, and telemetry export requirements: Symbol formats, debugger integration, and crash dump/core requirements: Applicable compliance requirements and required evidence: Representative workload: Desired result and acceptance criteria: Required investigation workflow (desktop, VS Code, server browser): PII classifications, redaction, and permitted destinations: Catalog and source access requirements: Local storage, rotation, and retention requirements: Server scope, hierarchy, and identity requirements: Artifact retention and data handling constraints: Delivery target, milestones, and per-capability acceptance criteria: Discuss compatibility, supplied artifacts, assistance, licensing, and fees before beginning. Sarvalekha supports Windows and Linux, with macOS underway. C++ is the first supported language; more languages follow C++ readiness. Confirm the toolchain and component-specific platform support for your evaluation. The Windows x64 server/Helper preview includes closed-file uploads, catalog hierarchy access, event search, and browser inspection. Managed organization sign-in, distributed queries, and hosted-service arrangements remain planned. Keep exact catalogs with the builds and logs they describe. Local investigation can work offline with the required artifacts. Under the target distribution policy, development binaries handed to customers for testing require publication of the exact catalog to the configured cloud destination before handoff. Catalog publication does not authorize upload of logs, source, symbols, or dumps. Resolve this policy and the planned publication workflow before distribution. Measure application CPU, memory, retained bytes (including catalogs), event-loss behavior, and investigation usefulness on representative workloads. For privacy evaluation, check redaction and build policy with synthetic data. Keyed-hash capture requires key-provider integration; the minimal C++ profile reports unavailable rather than exposing the original input. For UI profiling or analytics, identify application events, timing fields, and the questions to answer. Automatic UI instrumentation and aggregate dashboards are not part of the current foundation. Tracing already includes static span lifecycles, parent/child spans, cross-thread context, and log correlation. W3C header propagation and OTLP export remain delivery work. Symbol server support and expanded crash analysis are planned; current crash-log recovery covers retained committed events in supported dumps and cores. Agree the required formats, integrations, and acceptance evidence. Privacy and data-residency review: - Applicable framework and contract: GDPR/DSGVO, German sector rules, UK GDPR, DFARS, ITAR, FedRAMP/CMMC, DOJ Data Security Program, HIPAA, or another requirement. - Permitted storage/processing locations, recipients, remote support, backups, hierarchy nodes, and any required transfer mechanism. - Synthetic sensitive values for capture-time redaction and full-artifact review. - Treatment of indirect identifiers, tokens, static catalogs, source, and dumps. - Retention/deletion, encryption, key custody, and required assessment evidence. Sarvalekha classification is developer-declared. Destination metadata is not geographic egress enforcement; native-file uploads do not sanitize fields. Use the compliance guide at https://sarvalekha.com/compliance for the control mapping and official sources. No product certification is implied. Server diagnostics roadmap discussion: - Priority: qualify crash-log recovery and the customer/server workflow. - Symbol server: exact-build symbols, source references, and debugger needs. - Advanced diagnostics: correlate crashes and identify missing evidence. - Adaptive AI: eligible client installations, approved additional evidence on the next matching crash, policy expiry/revocation, and resource limits. - Success criteria: evidence completeness and customer investigation turnaround. Adaptive collection is planned; it cannot restore data missing from a prior dump. Distributed cloud, tenancy, and identity requirements: - Tenant, organization, project, application, and customer ownership boundaries. - Local, cloud, and hybrid topology; catalog routes and planned distributed queries. - Replication/failover, locations, retention, quotas, and operating responsibilities. - Entra ID/Active Directory, OIDC, SAML, LDAP, Kerberos, Firebase, or local accounts. - Provider-managed MFA/passkeys, email/social sign-in, groups, and role mapping. - Separate workload identities for builds, Helpers, peers, queries, and exports. Enterprise/provider integrations and distributed administration remain planned; current preview access uses configured certificate grants and an owner session.