Current pilot information
Security controls, with explicit limits.
The provider key is configured on the server and is not bundled into the web app. A separate pilot access code is required. The server restricts provider calls to a fixed endpoint, applies a timeout, allows one concurrent query and limits attempts per process.
Quota state is in memory and resets on restart. This is a single-instance private pilot, with no multi-user identity, durable tenant quotas or per-user audit trail. Public multi-tenant hosting requires additional work.
Deployments require HTTPS and operator review. No uptime SLA, security certification or regulatory authorization is claimed. Report suspected vulnerabilities without including live credentials.