Enterprise portal
Furnish or pull. The firewall is the product.
A lender cannot pull without a permissible purpose, an active consumer grant, and a thawed file. A furnisher cannot write an unattributed fact. Production signing is a KMS or HSM; a file key exists only behind dev-signer.
1. Lenders: purpose lock
FCRA §604.
PullFirewallruns purpose, consent, then freeze before it folds. Tenant screening cannot emit a mortgage score. Marketing is not a purpose Origin can state.2. Lenders: the look is the audit
A completed pull writes
FileAccessedon the consumer's chain. A blocked pull writesAccessRefused. A deciding purpose is incomplete untilDecisionRecorded. Open a demo file's compare page to see consumer vs lender.3. Furnishers: provenance is a constructor
NewEntry::newrequires provenance by value. Orphan collections and unverifiable items are held out of scoring and disclosure by the fold, not by a boycott list.4. What this portal will not do
It will not accept a production API key on GitHub Pages. AWS KMS and GCP Cloud KMS cannot sign Ed25519; Origin fails closed rather than pretend. Bank AIS (OBP / XS2A) is a fixture-mapped source, not a live bank connection on this site.
Crates: origin-api, origin-ledger. All three portals.