RECORDSECURITY & DATA PATH

Where your documents go,
and what never sees them.

This page holds no certification and claims none. What it can tell you is the path a document takes, which component is allowed to hold it, and what this deployment is not permitted to do at all. Every external operation fails closed — a control opens only after the one before it is qualified.

THE BOUNDARY, IN THE ORDER IT IS ENFORCED

WHAT HOLDS WHAT

Tenant identity is derived server-side from an authenticated session, never from an identifier the browser supplies. Provider credentials — authentication, billing, storage, content disarm — are managed server-side secrets; the browser may hold a provider’s own publishable token and nothing else.

CURRENT DEPLOYMENT CONTROLS

enabled

Customer document intake

Foundation private-pilot intake is approved after synthetic R2 qualification. Files go to the Foundation quarantine bucket only.

enabled

Content disarm and reconstruction

Foundation CDR Worker sanitizes quarantine source objects via tavonel-cdr-synthetic and writes immutable PDFs.

enabled

GPU OCR candidate processing

Foundation RunPod GPU OCR is qualified by the 2026-08-29 browser-to-ocr.json full-sequence evidence. Scale-to-zero and candidate-only review remain enforced.

human gate

Candidate promotion into a live world

Promotion is always an explicit human decision.

Intake, content disarm and GPU OCR opened only after the recorded 2026-08-29 full-sequence qualification. Promotion remains closed by design: a candidate becomes active only after an authenticated human approval.