Identity before access
Protected operations require a verified user and an active workspace membership. Capabilities are checked again on the server.
Security & boundaries • Public posture
NeuralStackly is designed to keep operational AI records inside explicit workspace boundaries. This page says what is implemented, what we refuse to collect, and what must still be proven before production launch.
Implemented foundations
These safeguards exist in the current application code and test surface. They are not a substitute for production configuration and independent verification.
Protected operations require a verified user and an active workspace membership. Capabilities are checked again on the server.
Tenant records use workspace-scoped authorization. Consultant access is explicit, limited, and revocable—not inferred from an email domain.
Plans and limits are enforced by server functions. Stripe events require a valid raw-body signature and successful events are idempotent.
Sensitive workflow changes create safe audit events. Public application functions cannot edit or delete that event history.
Deliberate boundaries
A useful AI register should make ownership and review visible without turning into surveillance or making legal promises it cannot keep.
Honest launch posture
The current branch has meaningful foundations, but production launch remains gated on credentials, operational exercises, delivery evidence, and incident alerting.
Implemented locally
Implemented locally
Implemented locally; production storage drill pending
Requires deployment verification
Requires production proof
Launch gate still open
NeuralStackly is an operational recordkeeping product, not legal advice, a compliance certification, or an employee-monitoring system.
Report a concern