App-boundary auth
The browser authenticates to OpenTrust first. The server then decides whether local evidence may be read.
Remote-safe posture
Shared-secret auth, CSRF checks, rate limiting, and audit logging now protect remote access paths.
Session-scoped trust
Successful authentication establishes a protected app session instead of exposing the underlying DB.
The intended flow is simple: authenticate to the app, then inspect evidence with operator confidence.