VEXTRACE CLIENT PORTAL — CLOUDFLARE PRODUCTION CHECKLIST The included client-portal.html is a static demonstration only. Before using it with real client data: 1. Protect /client-portal* with Cloudflare Access. 2. Require SSO or one-time PIN plus MFA according to client risk. 3. Build a server-side API using Cloudflare Workers. 4. Store structured case metadata in D1 or an approved database. 5. Store evidence in encrypted R2 with checksum metadata and malware scanning. 6. Enforce tenant isolation and role-based authorization server-side. 7. Record immutable audit events for views, uploads, downloads and changes. 8. Define retention/deletion and legal hold workflows. 9. Do not expose secrets in browser JavaScript. 10. Conduct a security assessment before production launch.