KERFFLOW SECURITY

Keep cutting and inventory workflows inside the right organization boundary.

KerfFlow separates public product content from the authenticated application. Operational data is accessed through secure sign-in, workspace membership, and role-aware application flows rather than exposed on the marketing origin.

01

SURFACE SEPARATION

Public content and operational workflows use different origins.

kerfflow.com serves static product information. Sign-in and authenticated screens live at app.kerfflow.com, where application routes and API traffic share the intended secure session origin.

  • Static public website
  • Dedicated authenticated application
  • No session or API client in the public site
  • Explicit cross-origin application links
02

IDENTITY AND SESSION

Authentication precedes access to workspace data.

The application uses protected sign-in and session flows. Public pages cannot act as an authenticated proxy or read organization data.

  • Secure application sessions
  • Protected authenticated routes
  • Explicit sign-in origin
  • Public pages remain stateless
03

ORGANIZATION BOUNDARIES

Tenant and role context govern operational access.

Inventory, cutting jobs, accepted results, and work orders belong to organization-scoped workflows. Application authorization evaluates that context before exposing or changing operational resources.

  • Tenant-aware resource access
  • Workspace membership context
  • Role-based operations
  • No customer data in public content

FAQ

Security questions

Does kerfflow.com store my application session?

The public site is static and has no authentication or API client. Authenticated work is served from app.kerfflow.com.

Is organization data public?

No. Operational resources are behind authenticated, tenant-aware application access.

Where should I report a security concern?

Use the official contact path associated with your KerfFlow account or deployment so the issue can be routed without sharing sensitive details publicly.

NEXT STEP

Open the secure application workspace.

Create a workspace or sign in at the dedicated application origin.