Draft: independent native-language and legal review required.

Security

Separate public pages, demo and operational data

The architecture is built around least access, isolated boundaries and reviewable history. No compliance certification is claimed without separate evidence.

Data boundaries

The public website does not read operational databases. The demo uses only fixed synthetic data on a separate origin.

Access and tenancy

The working application and API are separate boundaries. Roles, data scopes and tenant isolation must be verified in the target environment.

Audit and recovery

Critical changes, rule versions and administrative actions should be traceable; backup and recovery are proven through exercises.

Integrations

Secrets do not enter the browser or repository, incoming data is validated, and external calls are restricted to approved destinations.

WagonFlow / Pilot

Start with the data you already have

In a focused working session, we map sources, critical events and a pilot scenario. No production-system connection is needed for the first conversation.