SURFACE SEPARATION
Public content and operational workflows use different origins.
kerfflow.com serves static product information. Sign-in and authenticated screens live at app.kerfflow.com, where application routes and API traffic share the intended secure session origin.
- Static public website
- Dedicated authenticated application
- No session or API client in the public site
- Explicit cross-origin application links
