SECURITY AND TRUST

Security is a product requirement.

Here is what is available in the prototype and what must be implemented before production use.

CURRENT APPROACH

Protection by design — with clear limits.

Do not upload confidential documents until a secure production deployment has been independently verified.

♙

Server-side API secrets

Claude credentials belong in Cloudflare encrypted secrets, never in client-side code.

🔒

Private live AI

Live mode remains disabled by default. Cloudflare Access and additional server-side authorization are needed.

◉

Human verification

AI outputs require review and should not be treated as authoritative records.

▥

Storage limitations

The prototype stores demo records in browser local storage, not an audited multi-user cloud database.

⊘

Limited access

A public production rollout requires auth, quotas, abuse mitigation and audit controls.

▣

Document privacy

Use synthetic data for demonstration; production retention and deletion policies are not finalized.