Control-plane data
Only what the product needs
Account email, workspace and device metadata, policy acceptance, entitlement references, bounded target coordinates, operation state, and redacted audit events.
Security · Minimize · Isolate · Recover
See how WLOC Cloud limits browser access, isolates tenant-scoped operations, minimizes stored data, labels evidence honestly, and keeps recovery controls reachable.
Engineering controls and automated tests · Independent review pending · No certification badge implied
System trust boundary
The browser does not connect directly to the data plane. Passing one security boundary never silently upgrades the evidence produced by the next layer.
Data minimization
These are product and architecture contracts, not a claim of external certification. The public Privacy Policy is effective; the separate Cloud engineering legal documents remain formal-review drafts.
Control-plane data
Account email, workspace and device metadata, policy acceptance, entitlement references, bounded target coordinates, operation state, and redacted audit events.
Never persisted
Profile bytes and the EAP password transit Worker memory into an explicit one-time, no-store download. They are not retained in control-plane databases, KV, Durable Objects, queues, analytics, structured application logs, or fixtures.
Logs and analytics
WLOC structured application logs use field allowlists and redaction. Product analytics excludes email addresses, precise coordinates, tokens, device secrets, and Profile payloads.
It includes a CA root certificate, IKEv2 payload, and EAP credentials. WLOC does not call it a signed Profile until CMS verification is proven, and it does not call device-specific credentials hardware-bound. Review the install and removal guide before continuing.
Access control
UI state is never treated as an access-control decision. Every protected operation must re-establish identity, scope, capability, and mutation safety at the API boundary.
Control 01
Workspace and resource scope are checked together before an operation is loaded.
Control 02
Mutation requests require an authenticated session, exact-origin controls, and CSRF protection.
Control 03
High-risk support actions require separate identity, recent authentication, a reason, user authorization, and audit.
Control 04
The marketing Worker has no Cloud product-data binding; operational data stays in the Cloud control plane.
Evidence semantics
WLOC separates control-plane intent, Gateway readback, device evidence, and the tester's target-app confirmation. Labels state exactly which layer produced the evidence.
target_syncedawaiting_confirmationrestore_submittedmanual_confirmationRecovery contract
Restore, Revoke, Emergency Stop, Export, and Delete Account remain reachable under unpaid, refunded, frozen, restricted, and pending-deletion states. New Apply or Provision may be unavailable; only a server-enforced gate is treated as access control. Restore remains reachable.
Narrow browser boundary
The browser bundle receives no Gateway bearer token, Access credential, EAP password, or server-side secret. Profile bytes transit only during an explicit one-time, no-store download to the authorized device.
Review the security boundaryMinimized persistence
Profile content and the EAP password pass only through Gateway and the one-time response stream. WLOC does not retain them in D1, KV, R2, Durable Objects, Queues, product analytics, structured application logs, browser-side storage, or fixtures.
Read the Profile guideRecovery contract
Restore, Revoke, and Emergency Stop remain reachable under unpaid, refunded, frozen, restricted, and pending-deletion states. Gateway readback and final device confirmation remain separate.
See the recovery contractContact support@wloc.app with a reproducible description and redacted timestamps. Do not email Profile XML, EAP credentials, tokens, private keys, or raw traffic. No response-time SLA or external security certification is claimed here.
Review before you connect
Start with the fixed Tokyo Tower diagnostic, inspect each evidence layer, and finish with a device-side Restore check.
Authorized devices only · No card required · Restore remains reachable