- Encrypted in transit (TLS 1.2+), edge to origin.
- - Per-organization tenant isolation on every request.
+ - Per-organization tenant isolation on every request, backed by database row-level security.
- SSO (SAML & OIDC) with DNS-verified domains, plus MFA.
- Tamper-evident, append-only audit log.
- Open-source core you can read and self-host.
@@ -84,7 +84,7 @@
Tenant isolation
-
Every API request is scoped to your organization and authorized against your membership before any data is read or written. We are adding database row-level security as a defense-in-depth backstop so a single application bug cannot cross a tenant boundary. Cross-organization access is denied by default.
+ Every API request is scoped to your organization and authorized against your membership before any data is read or written. Beneath that, Postgres row-level security enforces the same boundary on every organization-keyed table: request traffic runs as a database role that cannot bypass it, so a single application bug cannot read or write another tenant's rows. Cross-organization access is denied by default.
@@ -167,7 +167,7 @@
In place today
- - Logical tenant isolation and access control
+ - Tenant isolation and access control, enforced in the application and by database row-level security
- Encryption in transit; object storage and backups encrypted at rest
- SSO, MFA, and role-based authorization
- Tamper-evident, append-only audit logging of authentication, configuration, billing, and data-export events
@@ -177,7 +177,6 @@
On the roadmap
- - Database-enforced row-level tenant isolation
- Formal policy set and access reviews
- Continuous control monitoring
- SOC 2 Type II observation window and independent audit
diff --git a/trust.html b/trust.html
index a332264..1a998e5 100644
--- a/trust.html
+++ b/trust.html
@@ -195,7 +195,7 @@ At a glance
- Encrypted in transit (TLS 1.2+), edge to origin.
- - Per-organization tenant isolation on every request.
+ - Per-organization tenant isolation on every request, backed by database row-level security.
- SSO (SAML & OIDC) with DNS-verified domains, plus MFA.
- Tamper-evident, append-only audit log.
- Open-source core you can read and self-host.
@@ -215,7 +215,7 @@
Tenant isolation
-
Every API request is scoped to your organization and authorized against your membership before any data is read or written. We are adding database row-level security as a defense-in-depth backstop so a single application bug cannot cross a tenant boundary. Cross-organization access is denied by default.
+ Every API request is scoped to your organization and authorized against your membership before any data is read or written. Beneath that, Postgres row-level security enforces the same boundary on every organization-keyed table: request traffic runs as a database role that cannot bypass it, so a single application bug cannot read or write another tenant's rows. Cross-organization access is denied by default.
@@ -298,7 +298,7 @@
In place today
- - Logical tenant isolation and access control
+ - Tenant isolation and access control, enforced in the application and by database row-level security
- Encryption in transit; object storage and backups encrypted at rest
- SSO, MFA, and role-based authorization
- Tamper-evident, append-only audit logging of authentication, configuration, billing, and data-export events
@@ -308,7 +308,6 @@
On the roadmap
- - Database-enforced row-level tenant isolation
- Formal policy set and access reviews
- Continuous control monitoring
- SOC 2 Type II observation window and independent audit