The confidential pay-matching backend — the server-side counterpart of the browser demo's salarysafe_backend.js.
Point the browser front-ends here
The candidate flow works against this backend with no code change — set the two globals before its script loads:
<script> window.SALARYSAFE_MATCH_URL = "http://localhost:8090/api/match"; window.SALARYSAFE_EVENTS_URL = "http://localhost:8090/api/events"; </script>
Invite links carry the backend-generated ?t=token; the candidate's configuration is fetched from /api/links/{token}/config, not embedded via ?d=, so the band never reaches the browser. The employer app's invite/results calls become async fetchs to /api/links and /api/roles/{id}/results.
Money crosses the API in major units; the DB stores minor (band_*_minor). Benefits are keyed by code. Only the direction (within/above = matched/not_matched) is ever returned to either side.