Private product previewReview the controlled design-partner evaluation path.Explore
Copperplate archive clerk sealing records

Trust, safety & evidence

Explainable, repeatable, recoverable

Shipping decisions can affect money, stock, and customer promises. The source is designed so sensitive local actions carry authority and evidence; provider recovery remains future work.

Authority

Server-owned scope

Tenant, client, and location scope are resolved on the server. The browser never selects its own authority.

Safety

Idempotent local writes

The synthetic source uses replay protection and version checks for local effects. No carrier booking handler is active.

Recovery

Unknown, not assumed

The target provider design treats an ambiguous response as reconciliation work rather than permission to retry.

Evidence

Reconstructable state

The source models versions, validation attempts, local operations, audit events, and outbox intent for synthetic orders.

Access and identity

Authority is explicit at every layer, and support access is never silent.

  • Roles and permissionsThe source derives visible company, client, and location scope on the server rather than trusting a client-side filter.
  • ApprovalsThe source models explicit approval counts and authority checks. Production approval policy remains an onboarding gate.
  • Support accessConsented, ticket-linked, scoped, expiring support access is a proposed control; it is not published here as an active support capability.
  • Carrier credentialsNo carrier credential is connected. Any future storage and isolation design requires provider-specific review and acceptance.
  • API and CLIThe API source uses the same server-owned authority boundary as the interface. The CLI remains an undistributed preview. See the developer docs .

AI trust position

AI may assist interpretation. Deterministic validation and authorised product services control shipping actions.

An AI-requested action must stay inside the requesting user's permissions and the company's policy.

It must show a preview of exactly what will change before anything is applied.

It must remain revocable and auditable, with the model named in the record.

ZeroClickShip AI is currently product direction and architecture. The workspace does not contain live model inference today.

Platform and data

Deployment posture, retention, and compliance work in progress.

  • Public-site hostingDesigned as a separate static service with no application, database, broker, carrier, or customer credentials. Production cutover is not yet verified.
  • Transport securityTLS and strict response headers are release gates. Encryption and credential controls for future provider services require separate evidence.
  • Retention and exportNo public retention period or export commitment is approved yet. These must be agreed in signed terms before customer data is accepted.
  • Privacy documentsThe public privacy notice, processor terms, subprocessor list, and data-processing terms remain approval gates.
  • CertificationNo ISO 27001 or other security certification is claimed.
  • UptimeNo live component feed or public SLA is connected. The status page reports that boundary explicitly. Read the status boundary .

Review the boundary with us

A future security review must distinguish source design, test evidence, deployed controls, and still-open gates.