ANCHOR POINTInformation care

Share carefully. Work confidently.

Put the right information
in the right place.

Start with a non-confidential question. We will agree the correct channel before sensitive project information moves anywhere.

The simple rule: do not send drawings, credentials, defence material, safety-critical instructions or private project data through the public website, WhatsApp or the Theory Assistant.

A practical sharing guide

Match the information to the channel.

OPEN

Safe to share publicly

Published information, generic engineering questions and resources already approved for unrestricted use.

Website, Hub or ordinary email
TEAM

Routine staff material

Non-sensitive templates, planning notes and ordinary administration with no client or controlled information.

Private Vault or staff email
PROJECT

Needs an agreed channel

Client identity, offers, drawings, measurements, contracts and non-public decisions.

Share only after access and retention are agreed
CONTROLLED

Stop and ask first

Passwords, recovery codes, defence material, export-controlled information and safety-critical operating instructions.

Not accepted in the current public system

Choose the channel

Where should I send it?

ChannelUse it forNever use it for
Public Hub / Theory AssistantGeneric theory questions with no project identifiersClient names, measurements, drawings, decisions or personal data
WhatsAppIntroductions and arranging a conversationCredentials, controlled files, commercial offers or sensitive instructions
Business emailNon-restricted scoping and ordinary correspondencePasswords, API keys, recovery codes or restricted material
Private VaultAuthorized internal/project records within agreed classificationRestricted data before written approval, or secrets stored as documents
Supabase SecretsServer-side service credentials such as the OpenRouter keyHuman passwords or general project documents

The systems behind the service

Each system has one clear job.

The public website, staff identity, private records, email and AI routing remain separated. No single provider is trusted with every layer.

PUBLIC DELIVERY

Cloudflare Pages

Serves public HTML, CSS, JavaScript and images. Network and security logs may include IP address, device and request metadata.

Does not hold private Vault documents by design.
IDENTITY · DATABASE · STORAGE

Supabase

Provides staff authentication, Postgres records, private object storage and the Edge Function. Row-level security and TOTP/AAL2 gates protect configured private data.

Service-role and OpenRouter secrets never belong in browser code.
AI ROUTING

OpenRouter Free

Receives public theory prompts through the Supabase Edge Function and routes them to an eligible model provider under the configured privacy constraints.

Availability is variable. Confidential/project prompts are prohibited.
BUSINESS EMAIL

Zoho Mail

Handles messages sent to the Anchor Point domain and the associated email metadata and attachments.

Email is not a password vault or restricted-file transfer system.
SOURCE CONTROL

GitHub

Stores website source and change history. Public-deployed source must be treated as readable by visitors even when repository visibility changes.

No secret, service-role key or credential belongs in commits.

Theory Assistant · experimental

Explain a concept.
Leave decisions to people.

The assistant helps with public engineering theory. Free live capacity can be busy, so reviewed local explainers remain available. Neither route provides design approval, equipment selection, a site method or an emergency instruction.

Try the Theory Assistant ↗
ASK

Concepts, equations, variable meanings, assumptions, unit checks, study pathways and questions to verify with a competent professional.

DO NOT ASK

“Approve this design,” “select this protection setting,” “tell workers what to do,” or any question containing confidential project information.

HUMAN DECISION

A named, competent and authorized person remains responsible for verification, applicability, safety and every consequential engineering decision.

The private Vault

Private access with deliberate limits.

01

Invitation only

No public sign-up. Initial access is limited to explicitly invited staff accounts.

02

Password + verified TOTP

Private data policies require authenticator assurance after successful enrollment and verification.

03

Role-aware access

Row-level policies restrict records and storage paths by authenticated identity and staff role.

04

Least necessary data

Do not upload data merely because storage exists. Classification, purpose, owner and retention must be known.

05

Recovery is designed

Exportable Postgres and object manifests provide an exit route; free-tier backups still require disciplined manual operation.

06

Secrets stay server-side

Provider credentials use protected function secrets. Browser-visible publishable keys are constrained by policies, not treated as secret.

Before a formal engagement

Ask for the evidence relevant to your scope.

Legal identity, appointed specialists, registrations, references, conflicts, standards experience and insurance must match the actual assignment. Relevant evidence should be confirmed during scoping rather than implied by a general website.

This launch candidate will publish only facts that are accurate, authorized and useful for due diligence.

Request engagement-specific verification →
How we workAsk before sharingHub