- core-api is the single public enforcement point for auth, tenant context and feature gating.
- Connectors, the AI gateway, workers and the compliance engine are internal-only: no host ports, short-lived internal JWTs with a per-service audience.
- Postgres row-level security on every tenant table, plus explicit tenant_id filters in the application.
- Side-effect endpoints require an Idempotency-Key; replays return the stored response, conflicts return 409.
- audit_events is append-only: a database trigger rejects UPDATE and DELETE.
- Credentials live only inside the connector that uses them; core-api can check status, never read the secret.
- The private model runs on your hardware; no ledger data is sent to a public AI API.
Security and tenant isolation
One public API, private everything else, RLS under every query, append-only audit.
4 min readsecurityrlsaudit