BEACON
Ten thousand pages.
Every one accounted for.
A reviewer’s workbench for very large pediatric disability case files. Beacon reads everything, cites everything — and decides nothing.
EVIDENCE, ILLUMINATED

Reviewer sign-in

Sessions are short-lived, single-tenant, and audit-logged. Five failed attempts lock the account temporarily.
Provisioned accounts (synthetic phase): Sam Svoboda · Brad Brabec — passwords as set by Sam, not displayed here. Try a wrong password to see failure and lockout behavior; recovery works too.

Password recovery

Enter your account ID. If it exists, a single-use recovery code is sent to the address on file. The response looks identical either way — accounts can't be discovered from this screen.

Reset password

In this demo the “emailed” code is shown below. It expires in 15 minutes and works exactly once.
Minimum 12 characters. Length beats complexity tricks.

Signed in

Session started · idle timeout 30 min · absolute limit 12 h · previous sessions unaffected until you sign out everywhere.
SYNTHETIC DEMO — NO REAL ACCOUNTS
Beacon · every control on this screen has a matching enforced contract in the foundation kernel (auth.py: scrypt-hashed passwords, uniform failure responses, lockout, hashed single-use recovery tokens, session rotation & expiry).