WOCTAM

Security

Effective: 24 August 2026

Before client invitation: the protected pilot hostname must be behind Cloudflare Access (or an equivalent identity-aware control) and Cloudflare Tunnel. Internal verifier port 8090 must remain loopback-only and must not be published to clients.

Current pilot model

The platform is being operated as a controlled human-in-the-loop pilot. Client users see upload, status, preview and verified exports. Classification, field/table capture and Final Verification remain internal operations workspaces.

Access boundary

The intended client route is HTTPS at app.woctam.com through Cloudflare Access and a tunnel to the loopback-only client workspace. No inbound router port forwarding is required.

Data handling

Uploaded documents should be limited to approved pilot data. Current readiness checks intentionally flag that a durable processing queue and malware scanner are not yet implemented, so unrestricted sensitive production uploads are not represented as production-ready.

Responsible disclosure

If you believe you found a security issue, do not include sensitive customer data in the report. Contact Woctam using the business contact address published on the main website.