Protected releases
Understand the signed runtime and integrity checks applied to licensed ONHOST CMS products.
## Packaging model
Protected PHP products receive an ONHOST runtime bundle during upload. The bundle has signed configuration and manifest data, while each protected source file checks its own integrity before it can execute. The resulting release contains no public licence key or browser-side secret.
## Stable failure behaviour
The packaging service rejects invalid or unsafe source before a customer can download it. A missing runtime, invalid signed state or unavailable validation service returns a controlled licence response instead of causing a PHP fatal error. After a valid live check, a signed offline grace period can cover short connectivity interruptions.
## Operator responsibilities
Keep the complete protected package together, do not rename or remove its runtime directory, and deliver updates through the product release workflow. If a customer needs to move a licensed installation, use the licensing workspace to release or bind the domain rather than editing protected state files.