Security claims limited to controls this website actually implements.
Website security is different from the security architecture of a client engagement. The controls below describe this application and its lead-capture flow; project-specific requirements belong in a signed scope and technical design.
Encryption in transit
Production traffic should be served over HTTPS by the deployment platform. This page does not claim encryption controls beyond the website stack and configured providers.
Server-side provider credentials
HubSpot, Anthropic, SMTP, Turnstile, and blueprint-signing credentials are read only by server endpoints and are never included in client application code or URLs.
Validated and abuse-checked input
Inquiry endpoints use structured Zod schemas, normalized field limits, explicit errors, honeypots, and server-verified Cloudflare Turnstile tokens before provider calls.
Consent-aware analytics
Google Analytics 4 is not loaded until analytics consent is granted. Advertising storage is denied in the implementation.
Honest success states
The embedded Calendar schedule loads only after the required internal inquiry email is accepted. HubSpot synchronization, blueprint generation, PDF creation, and visitor delivery are reported separately so one completed step cannot be mistaken for another.
Constrained AI processing
The blueprint model receives an accepted, sanitized operations summary, has no tools or browsing, and must return a fixed validated schema. Out-of-scope requests receive application-owned refusal messages.
Report a website security concern
Use the contact form and state that the message concerns website security. Do not include active secrets, personal data, or exploit payloads in the initial message.

