Inspectable platform controls
- TLS, edge security headers, server-side roles, and opaque HttpOnly sessions
- Runtime-managed credentials with repository and client-bundle leak guards
- Explicit model-provider calls, labeled offline fallbacks, and data minimization
- Server-side role checks and scoped authorization on protected account and organization routes
