Security
Security is the foundation of the workflow, not a badge added afterward.
Operator reference
The current posture protects professional account, VIN, wallet, and record workflows while keycode provider execution remains gated pending full verification.
- 01
Protected Transport
Launch traffic is served over HTTPS, and sensitive browser-facing flows avoid exposing server-side secrets.
- 02
Approval-Gated Access
Professional accounts are reviewed before access, with authorization controls for launch-critical actions.
- 03
Secure Infrastructure
Public app surfaces use controlled Supabase and Vercel delivery paths with readiness evidence tracked separately.
- 04
Verified Claims Only
Security posture is stated from current evidence without claiming unverified identity, role, or audit coverage.
Evidence boundary
Controls stated from current proof
Payments handled by Stripe (a PCI DSS Level 1 certified processor); KeyCodes.ai does not store card data
No-secret logging rules
RLS and rate-limit risk list tracked before launch
Provider execution stays off until credential, protocol, privacy, and recovery controls are verified