Transport and browser policy
Production is served over HTTPS by Vercel with HSTS, a per-request nonce Content Security Policy, clickjacking protection, content-type protection, and same-origin browser controls.
Encryption boundary
Public transport is encrypted with HTTPS. Anonymous Assessment answers are not stored. Private-beta email identity is application-encrypted with AES-256-GCM; access material is HMAC-signed and stored only as a keyed digest. No broader provider encryption claim is inferred.
Authentication and access
Private reports use opaque IDs, signed bearer access, hashed 10-minute single-use codes, seven-day initial owner links, 24-hour independently revocable shares, and owner-visible content-free access logs. Public saved-report access is disabled.
Secrets
Configured service credentials and report cryptographic keys are read from scoped server environment variables. No report key, access token, code, answer, email, or artifact text is logged.
Input boundaries
Report APIs require JSON where applicable, strict payload limits, schema normalisation, origin and CSRF-style header checks, a honeypot, and MongoDB-backed shared rate limits. Public mode additionally requires a managed bot-control contract before it can enable.
Human authority
The public Demo and Assessment keep consequential external sends, pricing, exceptions, and decisions behind visible human gates.
Data minimisation
The anonymous Assessment asks only for calculation-changing ranges, priority, currency, and current system names. It asks for no name, email, company name, free-text brief, or uploaded file.
Retention and deletion
Anonymous Assessment state ends with Clear, reload, or tab close. Synthetic private-beta report records carry 30-day TTLs and owner deletion removes every report, answer, calculation, token, consent, and log record while retaining only a content-free deletion receipt. This beta default is not published as legal policy for real data. Contact retention remains separately unresolved.
Incident response
A suspected issue can be reported to engineering@dissfam.com. The Assessment publication flag can close the route and an exact release can be reverted; no response-time SLA is claimed.
Continuity and rollback
Production releases are bound to exact Git commits and Vercel deployments. Phase milestones and the pre-transformation baseline provide recoverable rollback points.
Model and agent limits
The public Demo and Assessment are deterministic browser software, not autonomous live agents. Client agent behaviour, model choice, permissions, fallbacks, and monitoring are installation-specific.
Integration failure
Public capability entries describe fail-closed stopping, preserved source state, named exception ownership, revocation, and rollback expectations. They are not proof of a tested client connection.