
surface
Canvas White-Label
Your brand on the surfaces, CueCrux machinery underneath
Canvas White-Label lets a team put CueCrux's surfaces in front of its own users, under its own brand, on its own domain. A consultancy delivering receipted research to clients, a compliance function serving internal stakeholders, or a product team embedding governed answers can present the experience as their own while the machinery underneath remains CueCrux.
The design principle is strict: branding never touches the hash chain. Colours, type, logos, and domain are yours; the CROWN receipts underneath are signed and hash-chained identically to any other deployment, and they verify offline with the same tools. A receipt rendered under your brand is exactly as checkable as one rendered under ours, because verification depends on Ed25519 signatures and the BLAKE3 spine, not on presentation. Nothing about white-labelling weakens the evidence.
Tenancy boundaries are enforced by the same primitives that govern everything else. Every connection binds to a passport, RCX capability tokens are scoped to tenant as well as tools and tier, and any receipt resolves to who acted under which grants. One tenant's trails are not another tenant's business, and the enforcement is per-request policy rather than configuration convention.
White-label deployments of the hosted surfaces land with the launch gate. Teams wanting to build ahead of it can run the local daemon today and design against the same receipts they will ship with.