Security
Append-only. Entries cannot be modified or deleted (WORM trigger).
Nothing here
No admin actions logged yet.
Nothing here
No risky events classified (everything human-likely).
PDF upload and tracer verdict — module pending dedicated logic (watermark trace pipeline).
Data Subject Requests
Export / anonymization flow — pending DSAR pipeline. Until then handle via privacy@traxmark.com.
No open DSAR requests.
IP allowlist
Content Security Policy
Saved to platform_config.csp. Serving the header requires a middleware deploy — stored config only (NOT RUN).