Tenant isolation
- Tenant-bound sessions
- Tenant-scoped queries
- Cross-tenant insert triggers
- Per-tenant audit chains
- Tenant-specific attachment paths
Security model
The controlled reference platform applies tenant-scoped authorization, exact-action permits, cryptographic integrity, anti-forgery controls, content-addressed evidence, restrictive headers, rate limits, deterministic audit chains, and production configuration gates.
Production dependency
Public authorization requires named target infrastructure, managed identity, external KMS/HSM custody, secrets management, monitoring, recovery exercises, penetration testing, accessibility review, legal and domain assurance, and accountable approval.