Tokens must be checked server-side for hostname and action. Invalid, expired or replayed tokens fail closed.
Prepared · not activatedA verified session, completed necessary survey and active access status are all required. Client-side locks never grant data access.
Enforced fail-closedProtected responses are no-store and noindex. Durable server-side rate limiting is required before any real detail delivery.
No public detail dataAdministrative mutations require an operator role, a fresh TOTP step-up and a single-use action nonce.
5-minute maximum proof ageThe public application exposes no route that can edit source code, DNS or deployment settings. Provider and repository accounts require their own MFA.
Separate production checkpointSource, number, method, approval and revision records are versioned. Production policy cannot be self-approved.
Human review requiredRaster-only limits, malware scanning, metadata removal, official-domain reference matching and a human decision prevent an uploaded image from becoming public automatically.
Prepared · storage and email disabled