Pilot Configuration

Controlled Launch

Maximum security discipline. Single accredited investor. Full operational verification before scale.

Pilot Parameters

Parameter Value
Investor Count1
Investor TypeAccredited HNW — Trusted Allocator
Access MethodCloudflare Zero Trust tunnel (private link)
AuthenticationOTP per signing session
Governance ModeTier 2 default (manual approval)
Backup ScheduleDaily encrypted rotation
MonitoringContinuous on port 3005
Exposed Ports0 (all tunneled)
Document FormatsPDF, DOCX (pilot scope)

Investor Experience Flow


  Operator creates session
         │
         ▼
  Secure link generated
  (Cloudflare tunnel URL)
         │
         ▼
  Investor receives link
  (encrypted channel)
         │
         ▼
  Zero Trust verification
  at Cloudflare edge
         │
         ▼
  OTP challenge issued
  (6-digit, 5-min window)
         │
         ▼
  Document presented
  in SDC viewer
  (no copy/print/download)
         │
         ▼
  Signing ceremony
  (OTP-verified, multi-sig)
         │
         ▼
  Certificate generated
  (ESIGN/UETA compliant)
         │
         ▼
  Funding intent captured
  (ledger-anchored)
    

Security Posture

Network Isolation

Zero exposed ports. All traffic routes through Cloudflare Zero Trust. No direct IP access to any service.

Document Control

SDC viewer prevents copy, print, download, and screenshot. Forensic watermarking enables leak traceability. Time-limited access tokens.

Cryptographic Integrity

Every document is fingerprinted (SHA-256), signed, encrypted (AES-256-GCM), and anchored to a hash-chain ledger. Deterministic processing ensures reproducibility.

Operational Discipline

Daily encrypted backups. Continuous health monitoring. All events logged to immutable ledgers. Manual approval required for all investor-facing operations.

Pre-Invite Checklist

# Item Verification
1Docker Compose stack runningAll 4 services healthy
2IPFS/Kubo node connectedPeer count > 0
3Cloudflare tunnel activeTunnel status: healthy
4Zero Trust policy configuredAccess restricted to invited identity
5Test document processedFull pipeline: ingest → sign → IPFS
6Backup chain verifiedRestore test passed
7Monitoring dashboard livePort 3005 responding
8Governance ledger initializedGenesis entry present
9OTP delivery testedCode received within 30 seconds
10SDC viewer testedCopy/print/download blocked

Scaling Plan

After successful pilot validation with the initial investor, the system is designed for controlled expansion:

Phase Scope Requirements
Pilot1 accredited investorFull manual approval, maximum security
Limited3–5 investorsPer-investor session isolation, concurrent signing
Growth10–25 investorsQueue management, automated Tier 1 operations
Scale25+ investorsMulti-node IPFS, load balancing, dedicated backup infrastructure

Investor Posture

The pilot is configured for a Trusted Allocator — a relationship-stage investor where operational friction is acceptable and expected. The system presents as infrastructure, not a sales deck. Every security measure is visible and intentional.

The system itself is the product demonstration. The investor sees sovereign infrastructure, not marketing.