From 6fdc6a36d9022760f79d4c5be120ca0bb0f29b66 Mon Sep 17 00:00:00 2001 From: Ray Clanan <115944+rclanan@users.noreply.github.com> Date: Wed, 30 Sep 2026 19:03:52 -0400 Subject: [PATCH] fix(trust): database row-level security is live, not roadmap Postgres RLS now enforces tenant isolation on every organization-keyed table in production (SaaSy-Solutions/mockforge#1087, rolled out 2026-09-30). Move it from the roadmap to the in-place list and describe it accurately. --- src/pages/trust.html | 7 +++---- trust.html | 7 +++---- 2 files changed, 6 insertions(+), 8 deletions(-) diff --git a/src/pages/trust.html b/src/pages/trust.html index 3627114..99e5c82 100644 --- a/src/pages/trust.html +++ b/src/pages/trust.html @@ -64,7 +64,7 @@
Every API request is scoped to your organization and authorized against your membership before any data is read or written. We are adding database row-level security as a defense-in-depth backstop so a single application bug cannot cross a tenant boundary. Cross-organization access is denied by default.
+Every API request is scoped to your organization and authorized against your membership before any data is read or written. Beneath that, Postgres row-level security enforces the same boundary on every organization-keyed table: request traffic runs as a database role that cannot bypass it, so a single application bug cannot read or write another tenant's rows. Cross-organization access is denied by default.
Every API request is scoped to your organization and authorized against your membership before any data is read or written. We are adding database row-level security as a defense-in-depth backstop so a single application bug cannot cross a tenant boundary. Cross-organization access is denied by default.
+Every API request is scoped to your organization and authorized against your membership before any data is read or written. Beneath that, Postgres row-level security enforces the same boundary on every organization-keyed table: request traffic runs as a database role that cannot bypass it, so a single application bug cannot read or write another tenant's rows. Cross-organization access is denied by default.