Security & compliance

Security built into every layer

From Postgres row-level security to encrypted secrets and immutable audit logs — your tenants stay isolated.

Tenant isolation at the database

Every table enforces row-level security scoped to your TenantId. Cross-tenant reads are impossible.

Encrypted in transit & at rest

TLS everywhere. Secrets stored in vault. Service-role access strictly server-only.

Immutable audit log

Every change is recorded with actor, IP, route and risk classification. Append-only by trigger.

Audited support access

Even your own staff cannot read tenant data without a time-boxed, logged support session.