Tenant isolation
Server-derived scope, API authorization, FORCE RLS and negative tests layer protection across tenant boundaries.
Tenant isolation, scoped provider credentials, deterministic guardrails, minimal telemetry and reversible enforcement are release gates, not optional features.
Account management and service monitoring are implemented. Traffic enforcement, continuity and recovery remain service-scoped and require current technical and safety evidence.
Current state is shown only after a fresh, schema-validated snapshot is loaded.
Open status evidenceThese cards describe product scope. Current delivery stage, runtime health, scope and freshness are reported separately from the validated public snapshot above.
Server-derived scope, API authorization, FORCE RLS and negative tests layer protection across tenant boundaries.
Every decision records actor, reason, evidence, scope, TTL and rollback state.
Bodies, credentials and session tokens are not collected by default.
The visitor path remains short. Configuration, verification and rollback stay visible to the operator at every stage.
No scan or active control starts without explicit scope.
Credentials and actions are scoped to one provider, tenant and service.
Release gates include failure and recovery, not only the happy path.
AegiFlow does not turn missing evidence into a reassuring zero. Every state links to its source, freshness and next action.
How this capability behaves in production — grounded in the platform's documented, current operation.
Self-hosted identity with passkeys and step-up verification, opaque server-side sessions, immutable releases with checksums and rehearsed rollbacks, encrypted off-site backups with monthly restore drills, and a public security.txt with a real disclosure channel. The Trust Center shows capability states with the same honesty the dashboard shows customers.
Ownership, certificate, origin health and rollback must pass before traffic protection changes.