Trust by design

Controls are visible. Production acceptance remains explicit.

The application includes organization-scoped authorization, encrypted evidence storage, MFA and passkey support, immutable audit records, fail-closed scanning policy, signed downloads, and human approval gates.

Application controls

Organization-scoped access, CSRF protection, secure sessions, recent-authentication checks, audit events, bounded uploads, and provider allowlists are automated and tested.

Deployment controls

Production PostgreSQL, managed object storage and KMS, managed secrets, malware/OCR services, external monitoring, off-site recovery, and independent audits remain release gates until accepted.

Responsible disclosure

A published coordinated vulnerability disclosure process defines scope, safe research boundaries, reporting, acknowledgement targets, and status updates. Do not send credentials or customer evidence through ordinary email.

Evaluate the controlled workflow.

Review current limitations and release gates before using real customer data.

Review current availabilityView product tour