1. Product-specific security boundaries
Security claims are scoped to the product that actually implements the control.
- AccessGuard and RevenueGuard use guarded public-target browser/network paths rather than unrestricted browsing.
- DomainGuard checks public DNS and explicit operator-supplied DKIM selectors; it does not mutate DNS automatically.
- ClientVault and InvoiceGuard keep explicit human review/decision gates instead of silently approving sensitive workflows.
- InvoiceBatch FR has no public invoice-upload portal; its product page, checkout and controlled intake remain separate, with product-specific privacy and data-processing terms.