Identity
Authentication establishes who is present; it does not by itself authorize a consequential operation.
Security
Neptlium separates identity, authorization, privileged operations, financial state and provider evidence. These are architectural principles, not claims of certification, insurance, regulatory approval or perfect security.
Control boundaries
Authentication establishes who is present; it does not by itself authorize a consequential operation.
Roles, ownership, policy and resource state remain server-enforced boundaries.
Provider secrets, service credentials and privileged commands stay outside public browser authority.
Operational transitions should remain attributable and reviewable rather than inferred from presentation state.
Missing credentials, unavailable dependencies or unverified capability must not become simulated success.
Consequential operations are designed to resist accidental duplication and unsafe replay.
Ownership, row-level controls and service boundaries constrain access according to the responsible subsystem.