Current-state security boundary
Security posture claims should come with evidence.
Access model
Production app routes require an authenticated session. Public routes are limited to marketing, sign-in, request-access, static trust pages, and health surfaces.
Session boundary
Protected pages redirect unauthenticated users to sign-in with a return path. Authenticated simulated-tenant QA is validated across production application routes. A physical platform-authenticator ceremony and real-customer identity proof remain separate human evidence lanes.
Transport and headers
The web deployment uses production security headers including HSTS, frame restrictions, content-type protection, CSP, and permissions policy.
Data boundary
Tenant security posture and evidence data must remain tenant-scoped and redacted in operational artifacts. Do not publish secrets, credential material, or passkey challenge data.
Known open evidence lanes
External audit claims, final certification artifacts, live Sentry alert-routing proof, physical passkey ceremony evidence, real-customer tenant QA, and long-duration soak evidence remain pending until validated artifacts exist.