Jurisdiction activation
Nothing routes merely because a state exists in the form.
California — disabled
Not part of the operating footprint. Server rejects CA even if a request is manually forged.
Florida — disabled
Not part of the operating footprint. Server rejects FL even if a request is manually forged.
Every other state — explicit activation
A state routes only when its two-letter code is placed in the server environment variable PV_ACTIVE_STATES after jurisdiction-specific review.
Default deployment is fail-closed: an empty PV_ACTIVE_STATES means no legal lead can route.