Tenant and scope enforcement
Tenant context comes from a verified Clerk organization, scoped API token, or signed internal bridge. Protected calls recheck active membership, explicit denies, resource scope, and field policy.
ServSignal separates implemented application boundaries from provider activation and independent verification. The status of each control matters as much as its design.
The application has deterministic authorization, revision, audit, token, QR, file-state, and AI-proposal boundaries. Provider configuration and external exercises are reported separately. This is an architecture and activation-status summary—not a penetration-test report, certification, or contractual SLA.
The browser is a presentation layer. Convex derives identity and tenant context, authorizes the operation and fields, validates the expected revision, and returns a projected result.
Tenant context comes from a verified Clerk organization, scoped API token, or signed internal bridge. Protected calls recheck active membership, explicit denies, resource scope, and field policy.
Restricted network values and credential references use separate projections and distinct permissions for viewing, editing, export, AI, offline use, and QR resolution.
Material writes carry expected revisions and idempotency keys, enforce deterministic transitions, and append history and audit records inside the authoritative transaction.
QR and request tokens use high-entropy opaque values, persist only as hashes, support expiry and revocation, and contain no site, asset, network, or credential data.
Uploads enter private quarantine and are checked for size, checksum, and detected MIME before a verified GuardDuty result can release them. Renderer qualification and live file contracts remain open gates.
AI can create cited proposals only; it cannot decide readiness, tests, approval, or technical writes. Production AI stays disabled until its guarded evaluation is approved and retained.
Product boundaries are explicit so a workflow record cannot be mistaken for a monitoring, vault, or certification product.
Repository and configured-provider evidence does not substitute for the independent security, scale, and recovery work still required before broad enterprise availability.
Security-dependent capabilities stay unavailable until their activation gates pass. The current engagement begins with one named rollout and an explicit operating boundary.
Review Guided Live Wave pricing