Server-side secrets
Provider keys and document-processing credentials belong on the server and should never be exposed in client code.
Security for Verity starts with tenant isolation, least privilege, server-owned calls, audit trails, and careful handling of source records.
Provider keys and document-processing credentials belong on the server and should never be exposed in client code.
Production authorization should separate who can add information, review records, search history, export records, and see sensitive details.
Important actions should leave source-linked evidence, review state, export history, and access logs.