Security and data handling
This page separates two different things: what this preview site does today, and the security controls the product is being designed to have. They are not the same, and the planned controls do not exist yet.
This preview
- This is a static site. It serves HTML, one stylesheet, local font files and one image. There is no server application behind it in this preview.
- There is no upload control, no form, no sign-in, no account and no document processing on this site. Do not send purchase orders or quotations.
- The pages contain no analytics, no advertising pixels, no session replay, no client-side scripts, no cookies and no browser storage. Every request this site makes is for a file on the same host, and the fonts are served from this site rather than a third party.
- Servers still see ordinary request information. Like any website visit, loading these pages means your browser asks the serving host for files, and that host can see routine request details such as IP address, time and user agent. The specific host, its logging configuration and any log retention period have not been confirmed for publication yet, so this draft does not state them.
- Everything published here is synthetic. The part number, quantities and prices in the worked example are invented for illustration.
Planned product controls
The following are planned and not implemented. They describe the design intent for the product, not the behaviour of this preview.
- Workspace separation for stored records and documents, enforced in the database as well as the application.
- Explicit roles, with review decisions reserved for an authorised person in the workspace.
- Retention and deletion behaviour approved by the owner before any real document is accepted.
- A named inference provider, region, contract and retention configuration recorded and approved before any live processing.
- Audit history for material decisions, and export of an internal review record.
No retention period, certification, encryption guarantee or provider behaviour is promised on this page. Those statements require configuration that does not exist yet and owner approval.
Reporting a problem
A monitored security contact has not been approved for publication yet, so this draft does not invent one. The owner must supply the reporting route before this site is published.