Identity
OIDC/JWKS token verification, verified-email provisioning and server-authoritative tenant membership.
This page separates repository-verified controls from provider and independent-assurance work that still requires external evidence.
OIDC/JWKS token verification, verified-email provisioning and server-authoritative tenant membership.
Tenant authorization is backed by PostgreSQL row-level security; adversarial tests cover REST and GraphQL boundaries.
API keys are shown once and stored only as digests. Webhook signatures and worker tokens use timing-safe comparison.
Administrative, billing, agent-decision and entity-merge actions have durable audit or ledger records.
Retrieved source content is untrusted evidence. Human approval does not execute external contact, payment or submission.
An isolated restore runbook and verification tool exist. Provider retention and a dated production restore drill require external evidence.