Deployment protection

Cloudflare Access policy

Production, branch aliases, and immutable preview hosts are protected by Cloudflare Access before any site content is served. The result is a protected same-origin static contract: the private origin serves document pages, JSON shards, and attachments as static assets rather than through a runtime API.

One-time-passcode owner allow policy

The allow policy contains exactly one configured owner email address and uses one-time-passcode login. There is no application login form, stored password table, or account storage in the app.

Protected deployment hosts

The protected origin includes the production pages.dev hostname, branch aliases, and immutable preview URLs. Access is enforced before HTML, JSON shards, attachments, or other static assets are returned.

Operational notes