Implemented in the product foundation
These are executable design boundaries with contract, hostile-input, and database tests. They do not by themselves make a deployed environment production-ready.
Current authority on every sensitive request
- OIDC authorization code flow with PKCE, state, nonce, and one-use transactions.
- Opaque, audience-separated sessions with idle, absolute, and assurance expiry.
- Current tenant, membership, case, role, capability, and AAL revalidation.
- Private, no-store authenticated responses and non-enumerating denial.
Exact objects, immutable history
- Create-only private object tickets scoped to one case, revision, and purpose.
- Worker-computed byte digest rather than browser-declared file trust.
- Encrypted sensitive metadata and observation-value envelopes.
- Append-only evidence decisions, version pins, idempotency, and audit receipts.
Required before hosted customer traffic
The local authenticated workflow is implemented, but a hosted pilot remains closed until the exact production environment is approved, composed, exercised, and independently reviewed.
Approved providers
Identity, database, object storage, queue, key management, extraction, region, DPA, and subprocessors.
Operational proof
Monitoring, rate limits, scanner behavior, dead-letter recovery, backup restore, deletion, key rotation, and incident runbooks.
Release assurance
Deployed security tests, dependency and secret checks, load/backpressure evidence, accessibility review, and independent penetration testing.
Reporting an access or processing concern
Do not attach documents, values, credentials, cookies, or access links to a support message. Preserve the safe reference code and time shown by the product. The controlled pilot will display its approved support channel inside the authenticated workspace.
For current public-release guidance, visit Help & pilot support.