A deliberately narrow beta
Security
The safest customer account and payment data is data this release does not collect.
Current boundary
- No customer authentication or account database.
- No payment, banking, wallet, seed phrase, or private-key input.
- No file uploads or free-form server-side customer submissions.
- The worksheet endpoint accepts only a public synthetic record ID, an exact acknowledgement boolean, and a finite campaign label; real-record worksheets fail closed.
- The origin authorizes only its first-party executable application script and embeds non-executable, release-bound JSON-LD metadata; it includes no third-party fonts, maps, or analytics client.
- Allowlisted, size-limited analytics events omit raw IP addresses and user agents.
Browser protections
Responses use a restrictive content security policy, frame denial, MIME sniffing protection, a limited permissions policy, and no-store handling for pages and APIs. The current Cloudflare fallback edge may inject a browser-insights beacon tag, but script-src 'self' blocks that third-party request before a response is received or the script executes.
Real-record release binding
A future rights-cleared projection must match separately configured digests for the exact projection, source artifact, and redistribution-rights contract. Internal checksums alone do not authorize publication.
Responsible reporting
Do not include secrets, personal information, or exploit instructions in an initial report. Use the current contact path published at garyvisionventures.com and identify MidwestAmalfi Atlas in the subject.