Data we expect
Operational contract data stays tenant scoped.
ControlLayer is designed for post-signature contract operations: contract registers, supplier records, site coverage, renewal dates, notice windows, compliance evidence, tasks, reports, and audit activity.
Customer documents and extracted operational metadata should belong to the tenant workspace that supplied them. Public routes are read-only orientation surfaces and do not accept contract uploads or create tenant records.
Private workspace records
Contract files, evidence records, OCR text, AI extraction candidates, and source spans belong behind authenticated tenant boundaries.
Metadata-only commercial posture
Billing meters may track counts and entity references, but source files, prompts, signed URLs, and payment credentials do not belong in billing records.
No self-service tenant creation
Public pages can explain access and pricing, but tenant setup is manually provisioned by an implementation owner.