Application security
The current web application configures security headers including CSP, HSTS, X-Content-Type-Options, Referrer-Policy and frame restrictions.
SECURITY & PRIVACY
This page documents what is visible in the current CoMaSy implementation and the data-governance questions that must be agreed for a pilot. It is not a certification, DPA or substitute for your organisation’s legal/security review.
CURRENT IMPLEMENTATION
The current web application configures security headers including CSP, HSTS, X-Content-Type-Options, Referrer-Policy and frame restrictions.
Pilot requests are validated server-side and rate-limited before lead records are created.
GA4 instrumentation is optional and is designed to respect explicit analytics consent before behavioural analytics events are sent.
Pilot scope should define which participant and cohort data are actually required before the exercise begins. Individual-level reporting is not treated as a default requirement.
PILOT DATA
CoMaSy is designed around observable scenario decisions. The pilot should establish exactly which fields are required, who may access results and whether reporting is individual, cohort-level or both.
ARCHITECTURE & SERVICE PROVIDERS
The current Konfydence application is built on Next.js/React with Prisma and PostgreSQL/Supabase architecture and is deployed through Vercel. The pilot workflow includes a Resend email integration when configured. Consumer checkout uses Shopify.
Deployment-specific subprocessors, regions, retention, data-processing terms and customer security requirements must be confirmed for the actual pilot environment. This page intentionally does not claim a certification or contractual control that has not been verified.
PILOT REVIEW CHECKLIST
LEGAL & POLICY LINKS
REQUEST A PILOT
A qualified pilot request should make the data model and review requirements explicit before scale.