Internal GCCAP operating surface

This page is retained behind the public client website.

GCCAP does not delete operating records, trial packs, hardware activation surfaces or evidence automation layers. They are preserved for authorised client portal, command-centre and internal operating use while the public website stays clean for airline first impressions.

Open portal access

Internal GCCAP surface

Control environment contracts, secret references, zero-secret scans, rotation and drift evidence.

The lab is the internal operating surface for P18. It keeps provider cutover blocked until GCCAP can boot staging and production from external secret references without exposing credentials.

StatusInternal / restricted surface. Not part of the public client walkthrough.

GCCAP
Sensor
Gateway
Evidence
Watchdog
Journey intelligenceRepresentative demo
APIs/api/env-config/*
PurposeSecret discipline
StatusBlocked until external references proven
Risk reducedCredential leakage

Operational layer

Lab controls

Use these APIs to maintain environment and secret evidence.

Env contracts

Runtime variables for local, staging and production.

Secret mappings

External references for high-risk credentials.

Zero-secret scans

Package checks for accidental secret leakage.

Rotation/drift

Secret rotation and environment drift evidence.

Governance

Secret handling boundary

P18 stores references and evidence only; it must not store real secrets.

  1. Use .env.example only inside ZIP packages.
  2. Use provider secret references rather than literal values.
  3. Run zero-secret scans before any handoff or deployment.
  4. Do not paste real production credentials into admin fields, docs or chat.