Tenant isolation
Every client account, cart, report, and export must be permission-controlled.
Security posture
GCCAP is designed around private client environments, internal operating surfaces and evidence controls that should not be exposed as public client pages.
StatusPublic information only. Client-specific data and internal operating records remain controlled.
Operational layer
These controls become mandatory as GCCAP moves from public site to live telemetry and client portals.
Every client account, cart, report, and export must be permission-controlled.
Gateways and integrations must authenticate before data enters the evidence chain.
No production secrets in public ZIP files, browser code, logs, or demo packages.
Sensitive access, report exports, manual changes, and AI actions must be logged.
Decision clarity
Security maturity increases by phase.