Security
Security practices that can be reviewed before delivery.
This page describes current public and delivery practices. It is not a certification, audit report, warranty, or substitute for engagement-specific security terms.
Access and identity
Access is scoped to the approved task, partner-managed identities are preferred, and ownership or removal decisions are reviewed during handoff.
Data and secrets
Public forms are for introductory business context. Credentials, regulated data, classified material, controlled government data, private keys, and other highly sensitive content should not be submitted through them.
Showcase isolation
- Read-only showcase routes are designed without live API calls or WebSockets.
- Showcases do not create customer accounts, accept payments, or use production customer records.
- Showcase pages are marked noindex and outbound navigation is restricted.
Traceability and checkpoints
Delivery records can identify approved scope, material decisions, current risks, evidence reviewed, handoff status, and the owner of the next action. The evidence required for a specific engagement belongs in its signed terms.
Review before expansion
Identity, access, data, vendor, logging, backup, incident, continuity, and assurance requirements should be documented before a live service or pilot expands.