Security model

Collect less. Restrict access. Delete on purpose.

The production system must be designed before the first SSN is accepted. This draft separates the marketing site from the future authenticated intake environment.

01

Hosted card processing

Use Stripe-hosted checkout so StateFormed does not directly store customer payment-card numbers.

02

Separate sensitive intake

SSNs, ITINs, IDs, and signed authorizations belong in an authenticated encrypted portal, not a public website form.

03

MFA and roles

Administrative accounts use MFA and role-based permissions. Access is limited to the people who need the information.

04

Audit logs

Record logins, data access, status changes, downloads, and document events.

05

Retention rules

Define what must be kept, for how long, and when sensitive data is redacted or destroyed.

06

Incident response

Maintain written breach detection, containment, legal review, customer notification, and recovery procedures.

Launch gate

The marketing site can launch first. The SSN intake cannot launch until authentication, encryption, access logging, retention, backups, and incident response are real—not placeholders.

Data flow

Payment and formation data follow different paths.

1. Public site

Package selection and non-sensitive educational content.

2. Stripe checkout

Payment handled by the payment provider.

3. Authenticated portal

Sensitive formation and EIN information.

4. Restricted admin

Review, filing status, and controlled document access.

Start My LLC/Corp