ProBackend

Security

Clear boundaries, stated carefully.

Only claims with a current code or runbook source belong on this page.

Read-only AWS access

Customers deploy a cross-account role protected by an external ID. No AWS keys are requested; the product does not mutate infrastructure.

Customer-owned CUR context

SpendLens uses the customer-owned CUR export with inventory context.

Article tenant and runtime boundary

Customer-facing article work is organization-scoped; article stages run as separate runtime services.

Discoverability control

An article marked seo.noindex remains reachable by detail URL but is omitted from listings and sitemap.

Reader export and deletion status

The existing export surface includes reader preferences, consent history, and briefed articles. Current UI says server-side profile deletion is not yet available.