Identity protection
Strong password rules, sandbox email verification, rate-limited sign-in, HttpOnly SameSite sessions, and mandatory Owner MFA.
Security is a product boundary
SRC Launch separates public discovery, customer data, operations, providers, secrets, and AI tools. The local mission validates the architecture while production services remain credential-gated.
Production penetration testing, malware scanning, email, storage lifecycle, and managed identity configuration remain staging boundaries.
Strong password rules, sandbox email verification, rate-limited sign-in, HttpOnly SameSite sessions, and mandatory Owner MFA.
Customer isolation and Owner permissions are enforced in data operations—not inferred from hidden buttons.
R2 object keys are non-public, ownership is checked server-side, downloads are private, and MIME, extension, name, and size are validated.
Customer outputs exclude provider wholesale cost, margin, internal notes, other customers, and unrestricted data access.
Approved knowledge produces grounded answers; unsupported questions escalate instead of inventing law, tax, approval, or account outcomes.
Public metadata and structured content never expose dashboards, KYC, documents, sessions, or Owner routes.
A production security contact and coordinated disclosure address must be configured by the Owner before public launch. Do not submit sensitive evidence through a public form.
Next step
Check your readiness, compare the supported states, or speak with SRC Launch before making a decision.