Request, verify, onboard, and upgrade
New applicants create their own login details, verify the email address, and enter a guided organization onboarding flow. Optional mail, product, and default-setting steps can be skipped and revisited later. Trial records remain preserved if access becomes restricted or the organization upgrades.
Assign seats, roles, and product access
The primary organization administrator can invite up to the organization seat limit, assign a reporting manager, and enable only the tools each seat needs. A seat can be limited to BRANDED, TEXTED, the Un-Ordinary Inbox, Support, or Evidence reports.
Use the organization logo and attachment library
Organization administrators upload a logo and designate standard-email and campaign accounts. Attachments from outbound and synchronized inbound messages are stored inside the organization library. Images and PDFs display beside message and campaign details.
Connect a mail provider
SMTP sends mail. IMAP copies mailbox folders and can append the final message to Sent. Verify both transports before using the account. Provider-managed accounts may use OAuth; other providers may require a generated app password.
Authorize the mailbox through Google and begin the INBOX copy.
Select a Microsoft account and grant mailbox access.
Enter the mailbox address and provider-generated app password.
Enter SMTP and IMAP host, port, security, username, and password.
Select the provider
Choose Google, Microsoft, Yahoo, Apple, or manual SMTP/IMAP.
Authorize or enter settings
Use the provider's secure flow or the documented host, port, and security mode.
Verify and synchronize
Confirm SMTP, IMAP, Sent-folder discovery, and the first mailbox sync.
DKIM and domain health
BRANDED checks whether the selected provider already applies aligned DKIM. A custom domain without signing can generate a BRANDED-managed key, publish the public TXT record, and verify DNS once.
mail.example.comv=spf1 include:example.net -allbranded1._domainkey.example.comv=DMARC1; p=noneCreate a controlled campaign
Choose the sending connection, add recipients with documented permission, provide HTML or plaintext (or both), and run preflight before queueing.
Campaign preflight
✓ Sender verified
✓ DKIM aligned
✓ HTML or plaintext body present
✓ Unsubscribe controls present
✓ 2 permitted recipients
Rendered email and source code
This dummy email is rendered as actual HTML beside escaped source code. Email bodies should favor table layouts and inline CSS for compatibility.
|
EXAMPLE COMPANY
Your July account update
Dummy content rendered as real HTML.
| ||
|
Hello Alex, Your example account is active. Review the dummy summary below.
| ||
| Example Company · 100 Example Street · Unsubscribe |
View the dummy HTML source
Your July account update
Hello Alex,
Open dummy dashboard
Synchronize and compose ordinary mail
Ordinary email uses the same selected connection, queue controls, DKIM path, raw EML preservation, Sent-folder append, and evidence recording as campaign email.
| From | Subject | Mailbox | Received | Status |
|---|---|---|---|---|
| [email protected] | Welcome to the project | INBOX | Today 10:42 | Synchronized |
| [email protected] | Meeting notes | INBOX | Yesterday | EML preserved |
| [email protected] | Invoice available | INBOX | Jul 22 | Synchronized |
Tracked links, open pixel, receipt-request headers, SMTP DSN when supported, raw EML, and report versions require no composer switch.
Add files that will be preserved with the sent-message evidence.
Queue control
| Recipient | Status | Attempts | Next action |
|---|---|---|---|
| [email protected] | Completed | 1 | Evidence saved |
| [email protected] | Queued | 0 | Await worker |
| [email protected] | Failed | 2 | Review SMTP response |
Evidence and reports
Review the raw-message hash, Message-ID, SMTP response, DKIM selector, recipient outcome, and observed tracking requests. An open request is a technical observation and not definitive proof that a human read the message.
Submission timestamp, server response, recipient, and connection details.
RecordedTechnical pixel event with timestamp, network, and user-agent information.
ObservedOriginal MIME structure, headers, HTML, text, and attachment metadata.
PreservedOrganization reports retain tracking IPs, timestamps, clients, request paths, hashes and communication evidence while removing local server paths and administrator internals. Platform administrators receive a separate technical PDF and JSON with full server and raw-detail tables.
Pair and operate an Android device
PAIR-EXAMPLE-7F3A-91C2
Administer organizations and user accounts
The Administration Center separates the permanent God Admin from delegated site administrators. God Administration can review every organization and hierarchy. Delegated site administrators can perform assigned global operations but cannot inspect or modify the God Admin account or its home organization. It controls organization state, sending pauses, capacity limits, user email addresses, account suspension, and administrator-reviewed password resets.
| Organization | Status | Limits | Administrative action |
|---|---|---|---|
| Example Operations | Active | 10,000 email/day | Open controls |
| Dummy Legal Group | Sending paused | 2,500 recipients/campaign | Audit read-only |
Contact the administrator and continue in-account
Contact administrator opens a structured ticket form. Organization support can be assigned internally or escalated to platform administration. Conversation PDFs remain available to the requester and administrators, and are generated on demand, when closed, or after thirty minutes of inactivity. The request appears in the user's Support Center and the administrator queue, and the conversation refreshes automatically while both participants are signed in. The form discloses requester-side diagnostic collection; only platform administrators can review requester IP, browser, Cloudflare and request metadata for troubleshooting.
Connection verification fails after STARTTLS. Waiting on administrator.
1 new replyUser and administrator replies appear within seconds while the ticket window is open.
The administrator mailbox sends a themed HTML update with a branded PDF conversation record.
Email Extractor evidence workspace
Every signed-in seat can paste source text or upload supported PDF, Word, Excel, PowerPoint, OpenDocument, CSV, EML, HTML, JSON, and text-based files. Sources, extracted text, addresses, exports, hashes, and forensic reports remain stored by organization and hierarchy.
Paste or upload
No UI file-count limit; server safety size limits apply.
Extract modern domains
Public TLDs such as .camp, .global, and punycode domains are supported.
Export repeatedly
Retained one-per-line TXT, comma-separated TXT, and CSV files.
Preserve evidence
HTML, JSON, and PDF reports plus hashes and extracted-text sidecars.
Obtain and test IP, carrier, and DNS credentials
IPinfo
Create an access token in the IPinfo dashboard. Select Lite for the free country/ASN endpoint or the paid Core/Plus product that matches the organization subscription.
Twilio Lookup
Copy the Account SID, create a dedicated API Key SID and secret, and enable the desired Lookup data package. A test line-type request may incur the provider’s fee.
Cloudflare
Create a custom token with Zone:DNS:Edit and Zone:Zone:Read restricted to only the organization domain. Avoid a Global API Key.
BRANDED storage
Secrets are encrypted with the installation master key and isolated by organization. Rotate or revoke them at the provider whenever needed.
Authenticate the domain used by the SMTP connection
BRANDED can sign mail with a managed DKIM key after the public TXT record is verified. SPF must authorize the servers that really transmit the mail, and DMARC evaluates alignment. These DNS records do not turn the BRANDED web server into a public mail-transfer agent; the selected SMTP account still performs submission and delivery.
- Connect and verify the SMTP account.
- Open DKIM and domain for that connection.
- Publish the generated DKIM TXT record.
- Add the exact SPF mechanisms provided by the SMTP service.
- Begin DMARC with reporting, review results, and strengthen policy deliberately.
Import, find, synchronize, export, and safely restore
The inbox composer can search saved email contacts and add a new one in place. Connected-account contact sync can always extract senders and recipients from synchronized messages. Google and Microsoft address-book sync additionally requires the organization to configure its OAuth web application under API integrations, authorize the matching mail connection, and grant the provider’s contact-read scope. Generic IMAP does not expose an address book.
Suppression restoration is restricted to organization administrators and requires renewed permission, a reason, and evidence. The restoration creates a fresh granted-consent record and an administrative audit entry.
Trace every sent pixel to its origin
Evidence → Tracking Pixel Statistics lists each outgoing message that carried an observation token. Open the item to see all open and tracked-link events, including timestamps, available IP addresses, browser or proxy metadata, and links to the original message and campaign.
Preserve exported messages, intelligence, and support images
Publish articles with safe HTML, social metadata, embeds, and analytics
Each organization can create one S!CRIBED! publication only after an organization administrator chooses a unique slug and title. Public pages use /blog/organization-slug and individual articles use /blog/organization-slug/article-slug.
Create
Open Organization → S!CRIBED! Publishing. Setup adds two editable draft articles and leaves S!CRIBED! unpublished until the administrator enables it.
Design
Choose a theme, colors, hero and social images, article layout, WYSIWYG mode, or sanitized HTML source. Scripts, forms, and unsafe active content are removed.
Distribute
Copy direct URLs, iframe code, oEmbed, RSS, sitemap, and JSON metadata. Article pages publish canonical, Open Graph, X/Twitter, and Schema.org metadata.
Measure
Organization-scoped analytics retain visits, IP or IP hash, browser, referrer, country, campaign parameters, bot classification, embed views, and recent L!ETTERED! subscriber events according to the selected retention setting.
Create company and employee pages that are more than a list of links
Open L!INKED! from the main navigation. Employees can manage their own page; organization administrators can create company pages and authorized employee pages. Every page remains organization-bound.
Choose one of five systems
Aurora Glass, Executive Atlas, Neon Arcade, Editorial Mosaic, and Cinematic Orbit use the same easy builder with dramatically different visual personalities.
Compose every format
Add rich biography text, sanitized HTML, tracked links, social SVGs, image galleries, audio, video, timelines, metrics, quotes, and tested embeds.
Control community
Comments and reviews may be enabled separately. Company managers can review source metadata; only God Admin can make a review private or delete it.
Measure responsibly
Visits and outbound tracking hashes preserve available IP, browser, referrer, country, Cloudflare, and UTM evidence for authorized analytics and PDF reports.
Technology, people, projects, and verified ways to connect.
Connect a company hostname and create a private B!RANDED! entrance
Company Admin and God Admin accounts may connect unlimited organization-controlled hostnames such as branded.example.com. The company hostname changes only the entry identity and theme. It does not replace, redirect, or weaken joseph.anthony.camp, which remains the definitive canonical site and login for the complete platform.
1. Create the record
Open Organization → Company Domains + Login Portal. Add the exact hostname, choose the provider workflow, and publish the displayed _branded-verify ownership token.
2. Route HTTPS
For a hostname in the same Cloudflare account, add it as another Published application on the named tunnel. For an outside account or registrar, use Cloudflare for SaaS Custom Hostnames or another TLS-capable reverse proxy that preserves the original Host header.
3. Verify health
Run the domain health check. B!RANDED! records DNS answers, certificate details, the well-known ownership response, provider state, elapsed time, and the exact administrator who initiated the check.
4. Design the portal
Choose company logo, optional background, colors, heading, welcome text, login button language, and footer text. Canonical B!RANDED! attribution always remains visible.
Cloudflare in the same account
- Open Cloudflare Zero Trust and the named tunnel already serving the canonical site.
- Add the company hostname as another Published application.
- Use the same local service shown in the Company Domains setup screen.
- Save the route and return to B!RANDED! for verification.
Cloudflare for SaaS or another registrar
- God Admin configures the platform fallback origin and optional encrypted Cloudflare API token.
- Create the exact hostname as a Cloudflare Custom Hostname, manually or from B!RANDED!.
- Publish the ownership and certificate-validation records Cloudflare displays.
- Point the company hostname to the platform CNAME target displayed in B!RANDED!.
- Wait for both hostname and SSL status to become active, then run the B!RANDED! health check.
Safe termination
Open the hostname, choose Terminate, read both warnings, type the full hostname, and confirm. Termination stops company-host access but preserves the company, user accounts, chat metadata, theme history, health checks, login outcomes, and immutable forensic chain. DNS and provider cleanup instructions remain visible after termination, and God Admin or the Company Admin may reconnect the hostname later.
Connect a domain, create a compact route, and preserve its observations
God Admin and Company Admin accounts can connect one or many organization-controlled hostnames. Joseph Anthony Camp can begin with joey.camp; another company can use its own apex domain or a dedicated subdomain. Open T!RACKED! → Domain setup for the current Cloudflare Tunnel and reverse-proxy instructions.
Connect
Publish the HTTPS hostname to the BRANDED service, add it under T!RACKED! Domains, and use the verification control before deploying a URL.
Create
Enter the long HTTP/HTTPS destination. Choose five random characters plus a custom suffix up to ten characters, or a fully randomized code.
Observe
Redirects and pixels preserve normal request context, a salted visitor hash, optional full IP, Cloudflare headers when supplied, and a linked SHA-256 event hash.
Report
Send an initial deployment email, every observation, or hourly, daily, or weekly complete PDF reports. JSON and CSV exports remain available from analytics.
T!RACKED! does not perform canvas, audio, font, or cross-site fingerprinting. Administrators must use it only with the disclosures, consent, lawful basis, and platform rules applicable to the deployment.
Private professional conversations with explicit identity controls
C!HATTED! profiles are private by default and there is no public or cross-company directory. Internal employees receive a directory containing only active C!HATTED!-enabled coworkers in their own company; external accounts receive no company directory. Exact username search and shared-conversation discovery remain bounded. External participants remain visibly labeled, one-time invitations expire or become invalid after use, and senders may remove their own messages at any time while immutable forensic records preserve the original content and deletion event.
Employees see conversations in which they participate and cannot see an external contact’s other chats. Company senior oversight is limited to internal-only company conversations unless the administrator is personally a participant. Verification marks classify identity and do not endorse a person’s statements. A company may assign its own verification and flair to employees and to external contacts who accepted that company’s invitation, without gaining access to unrelated communications.
Invoices, payroll, contracts, products, subscriptions, and provider-connected settlement
B!ANKED! is visible only to the organization’s Company Admin and specifically assigned B!ANKED! seats. God Admin receives read-only diagnostic oversight and cannot create, approve, settle, cancel, or edit financial records.
- Create company-specific invoices with unlimited line items, custom taxes, VAT, processing fees, terms, notes, due dates, products, services, contracts, subscriptions, payroll, purchases, contractor payments, and receipts.
- Record ACH, credit, debit, electronic transfer, SEPA, wire, and EFT transactions through sandbox, manual settlement, or company-approved hosted providers.
- Verify bank-account relationships through sandbox, manual evidence, or an approved verification provider. Never enter raw card numbers, CVV, online-banking passwords, or reusable bank credentials.
- Store W-2, 1099, VAT, tax, contract, and bank-verification files in the company database with encryption, hashes, access control, and immutable events.
Draft invoice workflow: invoices remain fully editable—including party, dates, terms, notes, unlimited line items, prices, discounts, taxes, VAT, and fees—until an authorized seated user chooses Approve final invoice + submit. Submission locks those fields and preserves the final version in the event trail.
Product lifecycle: use Edit from either B!ANKED! Products or S!HOPPED! Products to change SKU, description, pricing type, price, tax, VAT, processing fee, inventory, publication, or active status. Deactivation preserves historical orders and invoices.
Public products and services with B!ANKED!-connected checkout
S!HOPPED! is visible only to the Company Admin and assigned S!HOPPED! seats. It publishes approved B!ANKED! products into a responsive public store with carts, customer accounts, orders, invoices, payment status, receipts, fulfillment, and support.
- Create products or import catalog data from CSV, JSON, Shopify-style exports, and supported APIs.
- Control price, inventory, subscription interval, taxes, VAT, processing fees, visibility, terms, and product description.
- Keep customer identities and contractor/payee portals separate from company B!RANDED! administration accounts.
- Every successful store order creates linked B!ANKED! invoice, transaction, receipt, notification, and immutable evidence records.
S!HOPPED! seats can create and edit products directly from storefront administration. Shared product changes update the B!ANKED! catalog without granting access to payroll, contracts, or other financial administration.
Create, publish, and operate an isolated company tool from any compatible HTTPS API
The guided composer explains endpoints, methods, fields, headers, encrypted secrets, request bodies, response mapping, testing, assignments, direct company publication, panic controls, and health checks for a first-time API developer.
Tools can submit structured fields or bounded file uploads and can present JSON, text, research, images, art, audio, video, PDFs, documents, and other binary results. Optional HTML, CSS, and JavaScript remain inside an opaque no-network browser sandbox and never execute in the B!RANDED! server process.
- Create the organization-scoped tool shell and conflict-safe slug.
- Define bounded inputs, headers, response mappings, and encrypted secrets.
- Build declarative requests and an optional sandboxed presentation.
- Test the draft and assign company roles or individual memberships.
- Publish the immutable version directly as an authorized company C!ALLED! administrator.
- Use Internal Tools for private employee tools and public/external tools; public tools also receive a clickable external URL.
- Monitor runs, scheduled health checks, forensic events, and tool-only panic controls.
Start with the exact failing layer
Cannot send
Verify SMTP, sender ownership, DKIM readiness, queue error, and provider response.
Cannot synchronize
Verify IMAP host, port, security mode, password, and folder.
Campaign does not move
Check worker heartbeat, schedule, queue status, pacing, and daily limit.
Report is incomplete
Confirm final recipient outcome, raw EML preservation, and evidence-chain health.