Public site
The public experience is designed without advertising trackers or behavioral profiling. Standard server security logs may record request metadata for reliability and abuse prevention.
Member identity
Initial member accounts use a verified organization email and a one-way password hash. Authentication events, organization membership and access policy are enforced server-side. Future Google or Apple identities remain linked login methods and do not assign organization or platform roles.
Customer records
- Access is tenant-, organization-, site-, role- and grant-aware.
- Evidence is retained according to configured contractual and legal requirements.
- Original documents remain distinct from OCR, redaction and other derivatives.
- Cross-customer model training is disabled by default.
