Identity and tenancy
Verified-email WorkOS AuthKit, mandatory TOTP, server-side Convex membership checks, opaque IDs, generic cross-tenant not-found responses, and role-scoped transactions.
Our launch architecture separates products, rechecks tenant authorization on the server, constrains provider access, and fails closed when evidence cannot be verified.
No customer accounts, uploads, payments, or processing are enabled in the current marketing-only deployment.
Verified-email WorkOS AuthKit, mandatory TOTP, server-side Convex membership checks, opaque IDs, generic cross-tenant not-found responses, and role-scoped transactions.
Separate encrypted S3 buckets per product, customer/job-scoped keys, 15-minute single-object uploads, five-minute authorized downloads, and immediate access revocation on deletion.
MIME and magic-byte agreement, malformed/encrypted/macro/archive rejection, Office-container bomb checks, malware scanning, immutable originals, exact duplicate hashes, and processing budgets.
Textract output is directed into customer-controlled encrypted storage. Claude Sonnet is pinned in Bedrock us-east-1 with zero-data-retention mode; unsupported model configuration fails closed.
Citations are checked for product/tenant/job ownership, page, bounds, exact quote, derivability, field policy, confidence, contradictions, and unsupported negative answers.
Immutable, content-safe audit events. Operational events contain opaque IDs, timing, provider status, cost, and error classes—never filenames, document contents, prompts, answers, or quotes.
7, 30, or 90-day retention; 30 days by default after completion. Access is revoked immediately and active/backup copies purge within eight days.
Stripe-hosted checkout and customer portal. Raw card data never enters the platform. Signed, replay-safe webhooks update subscription access idempotently.
Do not include document contents or customer data. Send a concise description to support@certdraft.com.