Tenant-scoped records
Business records carry an organization ID and cross-tenant identifiers are rejected by scoped server queries.
VeriLocus treats location, access, credentials, and change history as security boundaries—not interface preferences.
Browser affordances make the product clear. Server validation, scoped records, cryptography, and durable evidence make it safe.
Business records carry an organization ID and cross-tenant identifiers are rejected by scoped server queries.
Roles shape the interface, while API routes independently validate membership and permission for every operation.
Provider tokens and secrets are encrypted with AES-256-GCM before storage and never returned to browser code.
OAuth sessions use secure, HTTP-only cookies backed by durable database records and server-side validation.
Location observations, assignments, provider events, and user changes retain source, actor, and timestamp.
Signed webhook bodies, replay windows, tenant links, and idempotency checks protect provider ingestion.
Cursor checkpoints, retry budgets, leases, and stale-state handling prevent silent or unordered updates.
Provider-linked actual positions cannot be overwritten by a manual drag or planned assignment.
VeriLocus documents the controls it operates today and avoids claiming certifications or capabilities that have not been independently established. Public-site visit alerts use a short-lived first-party session signal without fingerprinting or precise location.
Use verified identity, tenant membership, role capabilities, and an accountable record behind every operational change.