Security overview
Public entry and continuity controls are documented where the website can prove them.
Infrastructure topology, certifications, audit results and incident metrics are not published without approved records.This centre separates what the website can demonstrate from policies, operators and assurances that are not yet approved for publication.
A partial state means only the written public boundary is supported. It does not imply an audit, certification or production SLA.
Public entry and continuity controls are documented where the website can prove them.
Infrastructure topology, certifications, audit results and incident metrics are not published without approved records.No retention duration is presented as policy until legal and product owners approve it.
The previous page-authored deletion and tax-retention timelines were removed.Public examples avoid personal records and parent examples are labelled SAMPLE.
Consent ages, guardian powers and response times require an approved privacy record.A provider list is not currently approved for public release.
No vendor, hosting location or data-transfer claim is inferred from code or marketing copy.Public tools state their source, limitation and unavailable modes near the result.
Training-data and model-provider policies remain withheld until an owned policy record exists.The disclosure workflow is designed but no public security contact is verified.
A security.txt file will not publish a guessed inbox or response promise.No incident SLA or communication channel is claimed without an operational owner.
Service incidents remain an app/operator responsibility until the public policy is approved.This website does not simulate uptime or a live status page.
Availability requires production monitoring evidence, not a decorative green badge.Question, predictor and commerce surfaces identify source, method, limitations and app ownership.
Per-product provider and human-review detail remains gated by approved product records.Public results explain that they are planning or practice aids and may be challenged in the app flow.
No human-response SLA is published without a verified support route and owner.No certification badge appears on the public website.
Certification, audit and compliance claims require scope, issuer, validity and evidence.Security, grievance and privacy contact details stay withheld until the owner-fact and legal review gates approve them. Product entry remains available; policy escalation is not simulated.