# Portal Architecture

- `server/` repositories are the boundary for server-side Convex calls.
- `hooks/` contains client hooks for account, organization, avatar, app form, and access checkpoint state.
- `stores/` contains Zustand UI stores for portal chrome, account snapshots, and app permission checkpoints.
- `types/`, `utilities/`, and `validation/` hold shared contracts, pure helpers, and Zod schemas.
- `security/`, `trust/`, and `rate-limits/` are only used where runtime wrappers need production checks, trusted auth headers, or sensitive-route throttling.