SECURITY · ASK BEFORE SENDING

01 / 08

Know the boundary before data moves.

Vantnod is being built so the source, role, Aino suggestion, and human decision remain separable. Final production-region and provider claims will not be published before the Cloudflare migration and operating model are verified.

The audit line below is an illustrative interface example. It is not customer or production data.

ILLUSTRATIVE AUDIT LINE

LOCAL UI
Source
Document or transaction
Suggestion
Aino shows the basis
Decision
Human approves
State
Trail remains separate
DATA
No attachments in first contact
ROLES
Access follows the task
SOURCES
Suggestions link to evidence
AINOAino is reasoning from a source

AINO · RESPONSIBILITY BOUNDARY

A suggestion is not a decision.

Aino can help interpret finance, but the user must see what an observation is based on, how certain it is, and which action requires human approval.

Source
Shown before interpretation
Uncertainty
Shown beside the claim
Approval
A human makes consequential decisions

KEEP THE LAYERS SEPARATE

Source, suggestion, approval, and change must not collapse into one state.

Safe financial work must remain understandable to someone who is not a security or finance specialist.

  1. 01

    Role says who may act.

  2. 02

    Source says what a claim rests on.

  3. 03

    The audit trail says what actually happened.

ANATOMY OF AN AUDIT

Every decision keeps a route back to the source.

The structure makes responsibility inspectable. These fields describe the product model and do not depict a real company.

01
Source
A document, transaction, or other verifiable basis.
02
Actor
Who suggested, reviewed, or approved the action.
03
Role
Which permission allowed the person to act.
04
Time
When each stage happened.
05
Change
What changed from the previous state.
06
Decision
Whether it was an AI suggestion or a human action.
ILLUSTRATIVE ROW

Aino suggested · human approved · the change was recorded as a separate step

FOUR MECHANISMS TO VERIFY

A technical claim is published only when it can be evidenced.

The Cloudflare migration is ongoing. This view therefore shows the boundaries to verify and their current state, not old infrastructure presented as new truth.

  1. 01MIGRATION ONGOING

    Location and processing

    The final production region and processing chain will be documented after the Cloudflare migration.

  2. 02REQUIREMENT

    Company scope

    Every figure and action must be scoped to the active company at the server boundary.

  3. 03TO VERIFY

    Recovery path

    Recovery objectives and a rehearsed procedure will be published only with evidence.

  4. 04REQUIREMENT

    Server-side history

    A consequential action needs a server-confirmed actor, time, and company context.

ROLES AND ACCESS

Not everyone needs the whole finance view.

The role model follows the task. This track shows intended responsibility, not a promise of open invitations or live permissions.

01WHOLE

Owner

The company view and key approvals.

02TASK

Team

Only the view and actions needed for their work.

03REVIEW

Accountant

Sources, evidence, approvals, and the posting trail.

04LIMITED

External reviewer

Time- and subject-limited review access.

PARTNER REGISTER

Show the name, job, and state.

A provider is not presented as active in production until its connection and processing role are actually verified.

  • CloudflareMIGRATION ONGOING

    Application and data layer · Migration is ongoing. The final production arrangement is not yet claimed complete.

  • StripeNOT ACTIVATED

    Payments · No public payment activation or outcome claim.

  • MaventaNOT ACTIVATED

    E-invoicing · A possible future connection, not an availability promise.

  • Enable BankingNOT ACTIVATED

    Bank connections · No public bank connection or provider-approval claim.

Three questions for every connection

Three questions for every connection

  1. 01

    What does the service do?

  2. 02

    Which data can it touch?

  3. 03

    Where do the responsibilities of Vantnod, the provider, and the user meet?

BEFORE YOU SEND DATA

Start with a description, not an attachment.

First describe the country, company form, current finance tool, and the point where a decision slows down. Do not send sensitive material in the first message.

DO NOT SEND YET
  • personal identity codes
  • payroll data
  • bank statements
  • receipts or invoices
  • customer lists
  • accounting exports

Agree the secure transfer path separately.

If detailed material is needed, the channel, purpose, and retention boundary are confirmed before transfer. The public changelog shows what actually changes.

Open the changelog

ASK FIRST

Bring financial data only when the processing boundary is clear.

Ask about location, roles, deletion, Aino boundaries, or the audit trail. The first message needs no sensitive data.

Ask about security