Server-side API secrets
Claude credentials belong in Cloudflare encrypted secrets, never in client-side code.
Here is what is available in the prototype and what must be implemented before production use.
Do not upload confidential documents until a secure production deployment has been independently verified.
Claude credentials belong in Cloudflare encrypted secrets, never in client-side code.
Live mode remains disabled by default. Cloudflare Access and additional server-side authorization are needed.
AI outputs require review and should not be treated as authoritative records.
The prototype stores demo records in browser local storage, not an audited multi-user cloud database.
A public production rollout requires auth, quotas, abuse mitigation and audit controls.
Use synthetic data for demonstration; production retention and deletion policies are not finalized.