Server-owned secrets
Provider keys, service-role keys, JWTs, webhooks, and private prompts stay out of browser bundles.
Security
The architecture keeps finance calculations, provider access, ownership checks, and audit-backed mutations behind server boundaries.
Provider keys, service-role keys, JWTs, webhooks, and private prompts stay out of browser bundles.
Go validates Clerk identity and enforces access on every user-owned finance resource.
Model tools call application-owned APIs, never unrestricted database credentials.
Analytics and errors must redact PII, holdings, prompts, outputs, and financial amounts.