The account boundary
Security is part of the client journey.
Authenticated access
Client claim information is designed to remain behind sign-in rather than a public reference lookup.
Ownership boundaries
Account routes resolve the signed-in client and verify ownership before returning claim information.
Private correspondence
Messages and notifications are presented inside the account rather than exposed through public pages.
Controlled document architecture
Document functionality is designed for private authenticated access; live file storage depends on separate configuration.
Data minimisation
Public pages avoid private claim details, storage internals and unnecessary personal information.
Document handling
Designed for private access, clear about availability.
The Document Vault and upload flow are designed to support private, authenticated access. File-storage activation is configuration-dependent, so this public explanation does not claim that every account currently has live document storage.