loading…
Information separation, employer boundary, KYC posture, session security, and AI honesty limits — principles you can audit, not a substitute for independent certification.
Least privilege — access is capability-scoped, not inferred from role names alone
Separation of public, developer, and ops data planes
Secure session via HttpOnly cookies — no long-lived browser secrets
Human control for membership, KYC finality, and QA acceptance
Audit-friendly records — immutable evidence versions, logged decisions
Honest product claims — no fake certifications or invented metrics
Organizations contract with UNX Code. Developer surfaces never receive employer identity, contact data, margin, or internal risk notes.
Public portfolio and insights use only approved public fields. Client names are not invented for atmosphere.
Identity review is manual. Documents move through signed upload sessions; when upload and file-check integration is connected, checks run before submit — not Base64 dumps as the primary path.
KYC metadata and files are not stored in browser storage. When file-check integration is connected, pending or failed checks block submission. OCR is never the final identity decision.
AI may support drafting or triage in future ops tools. It does not auto-approve membership, auto-accept delivery, or fabricate success probabilities.
Until product decisions revisit external analytics, public telemetry stays on approved events and local to product events.
What we commit to on public and portal surfaces — not a substitute for independent audit.
Security and privacy issues go through contact — we do not fake ticket success offline.