Public deployment
Custom HTTPS frontend on Vercel; separate Hostinger API and PostgreSQL.
Evidence & system status
Recorded on 9 October 2026. This is a dated verification record, not a live uptime monitor or a payment receipt. Private identities, purchase IDs and infrastructure identifiers are omitted.
Custom HTTPS frontend on Vercel; separate Hostinger API and PostgreSQL.
Login, draft, review, submission, rejection and logout passed through the public hostname.
An incorrect request origin returned HTTP 403.
Capture without verified authority returned HTTP 503.
Integration tests used disposable PostgreSQL. Test fixtures are not live provider proof.
Source: the internal deployment record and an isolated synthetic smoke identity, which was locked and its sessions expired after the check. No customer records are published.
Deployment checks establish the evaluation workflow and unavailable-service refusal behavior. HTTP 503 does not prove that an available authority service rejects an invalid grant. A successful authorized payment has not been demonstrated.
Local verification on 9 October 2026 confirmed real PayPal sandbox buyer approval and matching order terms, with zero captures. That result has not been reproduced through the deployed application. Local canonical authority checks rejected changed terms on an unspent grant and rejected replay with HTTP 409, using a software test device and fixture payment. These checks do not complete deployed payment acceptance.
Signed human authority → exact order binding → independent buyer consent → protected execution and an authentic receipt.
Replay, tampering, concurrency and uncertain outcomes need verification across that complete deployed chain before the payment acceptance gate can pass.