Governance candidate
This page describes the current local, pre-operational design. It is not evidence of a hosted service, a completed privacy assessment, or jurisdiction-specific legal approval.
The contact form validates inquiry fields but has no approved delivery or storage sink. In this candidate, a validated inquiry is not delivered and is not intentionally retained by the application.
The architecture uses Supabase verified identity claims and active membership records for protected access when those services are configured. Essential session and CSRF cookies are part of that design. Display preferences and watchlist data may be stored locally in the browser. This candidate does not prove any hosted configuration or production retention behavior.
Repository code includes optional market-data and application service integrations. Actual providers, subprocessors, telemetry, cross-border transfers, and provider onward-use settings require separate deployment evidence and review. Sentry is not enabled by this reconciliation candidate.
The candidate includes verified-session boundaries, active membership checks, route-local permissions, input limits, same-origin CSRF controls, private cache directives, and redacted errors. These controls are design and local implementation evidence, not a certification or guarantee of absolute security.
A reviewed operative notice must establish applicable jurisdictions, lawful bases, data categories, recipients, retention and deletion rules, legal-hold handling, rights-request procedures, contact channels, and provider terms before production processing is authorized.