Skip to content

Security

Security controls with the boundary in view.

ValetLoop keeps the POS Switch Navigator deliberately small and treats private submissions as a separate operational boundary.

Private submissions

Optional property-plan requests and correction reports are private operational submissions. They accept bounded form fields, no file uploads, and are protected by server-side validation, duplicate handling, hashed rate limits, and restricted database access. Supabase/Postgres row-level security and security-definer submission functions are part of the repository design; provider configuration and production activation remain environment-specific.

Corrections are reviewed before they can change a public claim. A submission receipt confirms that the protected intake boundary accepted the request; it does not promise a response time or a research outcome. Use Report a correction for evidence concerns.

Operations and reporting

Application code keeps the navigator’s public evidence separate from private submission records. The research release is versioned in the repository, and directional comparison pages remain gated until the evidence threshold is met. Incident response, provider-side retention, backups, monitoring, and vulnerability handling require operational configuration and approval; this page does not claim a particular uptime, certification, SLA, or activated provider control.

To report a security concern, use Support or Contact. Do not send credentials, customer files, or secrets through a public form. Read Privacy for data boundaries, or use the Navigator.