Skip to page content
Full Graphics is active.

Local-first product boundary

Privacy

Veteran Mission Control’s production compensation core is designed to work without an account. Veteran benefit facts remain in the browser unless the user explicitly downloads, imports, or later consents to a separately approved transmission feature.

Browser-local records

Calculator inputs, conditions, dependents, SMC designations, historical scenarios, payment records, award attribution, planning records, service-identity overrides, activity history, accessibility evidence, and pre-restore safety copies use browser storage.

Portable JSON backups and browser-native PDF reports are created locally. They may contain sensitive veteran, medical, dependent, claim, payment, and planning information and are not encrypted by VMC after download.

Clearing browser storage, private-browsing data, or the browser profile may remove these records. Use Data & Backup for reviewed export and recovery.

Separate UAT environment

The invitation-only testing environment may use a dedicated Supabase project for tester authentication, roles, release manifests, invitations, and audit events. It is isolated from VMC production and must not receive copied production veteran workspace data.

UAT secrets remain server-only. UAT account, invitation, audit-retention, and deletion procedures are controlled by the testing activation and operations runbooks.

Prohibited transmission

VMC does not approve calculator facts, condition names, ratings, payment records, report contents, backup bytes, document text, claim identifiers, or personal information for analytics, advertising, session replay, public URLs, source control, or unrestricted logs.

Any future document processing, email integration, encrypted cloud storage, AI service, analytics, or collaboration provider requires a separate approved architecture, explicit user consent, minimum-necessary data, retention and deletion rules, and updated privacy disclosure before activation.

Production review is still open

Security and privacy automation does not replace the final domain-header check, UAT deletion exercise, incident tabletop, observability decision, accessibility evidence, or owner acceptance.