Controlled launch checklist
Launch readiness.
Implemented safeguards are distinguished from reviews and approvals that still require qualified external providers. “Implemented” is not a legal, security, or accessibility certification.
Operator identity
DocumentedNicholas Ekman carrying on business as AKELASENTERPRISES; official email contact is published.
Legal and privacy coverage
Operator-reported reviewThe operator confirms that independent Ontario counsel reviewed and approved the current public and paid launch position, including all thirty-one tools, regulated-data restrictions, contextual advertising, signature limitations, and the Quebec exclusion, on August 30, 2026.
Local processing
ImplementedOrdinary editing and conversion run in browser memory without intentionally uploading document content. Secure Link and signature-request links use temporary browser-encrypted storage.
Encrypted links
Operationally verifiedGeneric private routes, fragment-held secrets, fixed POST endpoints, streamed encrypted storage, Cloudflare edge and application rate limits, five-minute scheduled cleanup, immediate one-view metadata cleanup, and verified R2 deletion evidence are in production.
Cost containment
ImplementedEncrypted links have per-network and site-wide ceilings, 15-minute access, five-minute cleanup, a 15 MB free maximum, and paid-plan transfer ceilings.
Traffic capacity
Local tools scale; hosting upgrade requiredDocument processing occurs on each visitor’s device and static assets are served at the edge. The current Free Worker tier is not sized for millions of dynamic page requests per day. Before sustained traffic approaches the plan ceiling, upgrade Workers, enable budget and capacity alerts, measure Worker CPU and D1/R2 use, and complete staged load testing. Secure Link capacity remains deliberately capped until revenue and measured infrastructure use justify an increase.
Day Pass payments
Live and testedThe one-time US$3.49 plus applicable tax checkout is active and the public Stripe profile is complete. A controlled live purchase, browser restoration, full refund, webhook handling, and entitlement revocation passed. Continuing account-status monitoring remains an operational task.
Monitoring and alerts
Privacy-safe native monitoring activeCloudflare email alerts are enabled for a US$1 usage threshold, SSL certificate changes, HTTP DDoS events, and major or critical Cloudflare service incidents. Application monitoring emits only allowed route categories and generic status codes; full invocation logs and traces are disabled. Provider infrastructure may still attach ordinary request metadata. The site also exposes a content-free health endpoint. Cloudflare still handles ordinary request metadata as the hosting provider. These controls do not constitute an independent end-to-end uptime monitor; an external monitor is deferred to avoid adding another processor and because standalone Cloudflare Health Checks are not included on the Free plan.
Advertising
Pending Google approvalPublic ownership metadata and ads.txt remain installed. Advertising scripts and live placements are disabled pending account/site approval, consent configuration, and policy testing.
Legal review record
Operator-reported approvalThe operator reports Ontario counsel approval dated August 30, 2026. The written scope remains to be archived; this page is not independent verification of that approval or worldwide legal clearance. Material changes require renewed review.
Independent technical assurance
Outstanding before broader promotionIndependent accessibility review, penetration testing and cryptographic review, followed by remediation and retesting, are not complete. Internal tests and reported legal approval do not replace this work. No external certification is claimed; regulated use remains prohibited.