Features
Every capability below carries a status, and the status means exactly one thing:
Available built in and enforced by construction · Verified exercised and passing in a named environment · Adapter required the package ships the contract, you supply the implementation · Roadmap planned, not shipped · Not verified reasoned about, never run · Not supported deliberately out of scope
Storage and files#
| Capability | Status | Notes |
|---|---|---|
| Atomic local storage | Available | Stage → flush → verify → promote → rotate. An interruption cannot leave a half-written save. |
| Retained backup per slot | Available | Retention is a count (default 1), not a history. |
| Recovery and quarantine | Available | A damaged primary is moved aside with a reason and the newest valid backup is restored. |
| Slot model | Available | Any number of named slots, each a directory, each with its own backups and revision sequence. |
| Metadata readable without a key | Available | What makes a "Continue" menu cost kilobytes instead of megabytes. |
| Custom storage backend | Adapter required | Implement ISaveStorage for a platform whose storage is not a filesystem with atomic renames. |
Versioning and containers#
| Capability | Status | Notes |
|---|---|---|
| Versioned container | Available | Every format version it has ever written remains readable. |
| Schema migration | Available | Ordered, journalled, bounded chain, registered as code. |
| Unknown-member preservation | Available | PreserveAndReport by default, so a downgrade does not wipe data. |
| Forward-compatible read | Available | Off by default; opt in per call or in configuration. |
Security#
| Capability | Status | Notes |
|---|---|---|
| Integrity (CRC32 / SHA-256) | Available | Verified before anything is parsed. |
| Authentication (keyed HMAC-SHA256) | Available | Separate key from encryption, on purpose. |
| Encryption (AES-256-CBC + HMAC) | Available | Encrypt-then-MAC; tag verified before decryption. |
| Bounded decompression | Available | Declared size, ceiling and expansion ratio, enforced before and during. |
| Key management | Not supported | The framework never stores, generates, derives or rotates a key; ISaveKeyProvider is the only source. |
| Rollback (replay) protection | Not supported | Detecting a restored older save needs a server-side sequence. |
Save behaviour#
| Capability | Status | Notes |
|---|---|---|
| Autosave | Available | Debounce, ceiling, minimum gap, coalescing, one queued write, pause flush. 0.03 ms idle tick. |
| Checkpoints | Available | Ordinary saves in their own slots, so they inherit everything. |
| Manual save offload | Available | Storage.OffloadWritesToThreadPool, off by default; the projection stays on the caller's thread. |
| Multi-process coordination on one root | Not supported | Atomic promotion keeps either version intact; the later writer still wins. |
Unity objects#
| Capability | Status | Notes |
|---|---|---|
| GameObject and component capture | Available | Identity, transform and each supported component. |
| ScriptableObject persistence | Available | Through PersistableScriptableObject, which gives an asset an identity. |
| Persistent object identity | Available | PersistentId; InstanceID is never used. Project-wide validation for missing, duplicate or unstable ids. |
| Restore under a policy | Available | Seven policy questions, three presets, every disagreement reported with what/why/fix. |
| References | Available | Stored as identity; resolved through your resolver, an injected one, or the session index. |
| Prefab reconstruction | Available | Only through your IPersistencePrefabFactory; the package never calls Instantiate. |
| Content types as values | Not supported | Texture2D, Material, Mesh, AudioClip, Sprite, Shader are refused with a suggested key-based alternative. |
Cloud#
| Capability | Status | Notes |
|---|---|---|
| Vendor-neutral transport seam | Available | ICloudTransport: four methods over opaque bytes. |
| Sync, conflicts, offline queue, retry | Available | Framework code, verified against in-memory and HTTP-shaped doubles with failure injection. |
| A specific provider | Adapter required | Implement the transport. Nothing vendor-specific ships, by design. |
| Firebase / PlayFab / REST / Steam adapters | Roadmap | Planned, not shipped. See the adapter roadmap. |
| Real provider semantics | Not verified | No service was reachable in the verification environment. |
Editor tooling#
| Capability | Status | Notes |
|---|---|---|
| Guided setup with presets | Available | Minimal, Recommended, Hardened — each explains itself before it applies. |
| Validation with remedies | Available | Two depths; every actionable finding carries what/why/fix. |
| Storage probe | Available | Writes, verifies and deletes inside its own _probe directory. |
| Save Browser | Available | Metadata and file listing only — never payloads or keys. |
| Platform support matrix | Available | Claims as data, with evidence and how to reproduce each one. |
| Generated code | Available | From your configuration, public APIs only, with Copy. |
Verification#
| Capability | Status | Notes |
|---|---|---|
| Edit Mode suite | Verified | 582 tests, Unity 6000.6.0f1, Windows x64. |
| Fuzz, corruption and culture tests | Verified | Including the culture defect the IL2CPP run found. |
| IL2CPP player probe | Verified | 12/12 checks in a release player, exit code 0. |
| Measured performance | Verified | Shape, not promises: Performance. |
| Consoles, mobile, WebGL, macOS, Linux | Not verified | Platform-neutral code, no run. See Platform support. |
Where the detail lives#
Every row above links to a page that explains it: documentation, the platform support matrix, the limitations and the roadmap.