Security and trust

Private proof needs proper doors, not polite labels.

Capshur separates personal, employer, business and union records at the data and permission layer. The interface explains the boundary, but the backend enforces it.

Protection model

The interface and backend tell the same story.

A glossy switcher is useful only when every API, file view and query follows the selected space. Capshur is built around that shared contract.

Exact space boundaries

Records, uploads, calendars and management actions carry the specific space identifier, not only a company label.

Private storage

Evidence files are held privately and viewed through short-lived access after permission checks.

Assignment-aware review

A manager needs an explicit worker assignment inside the same Work space.

Private Vault isolation

Personal and private-vault evidence remains owner-only unless the owner deliberately shares an item.

Visible extraction

The worker sees the original image, extracted result, confidence and company profile before confirmation.

Versioned audit history

Recognition versions, corrections, status events and restored rules remain traceable instead of rewriting the past.

Human confirmation

OCR is evidence assistance, not invisible authority.

Low-confidence fields remain visible, workers can correct repeated rows, and company profiles cannot silently retrain themselves from private records.