Skip to content
Finanly

Security and tenant isolation

One public API, private everything else, RLS under every query, append-only audit.

4 min readsecurityrlsaudit
  • core-api is the single public enforcement point for auth, tenant context and feature gating.
  • Connectors, the AI gateway, workers and the compliance engine are internal-only: no host ports, short-lived internal JWTs with a per-service audience.
  • Postgres row-level security on every tenant table, plus explicit tenant_id filters in the application.
  • Side-effect endpoints require an Idempotency-Key; replays return the stored response, conflicts return 409.
  • audit_events is append-only: a database trigger rejects UPDATE and DELETE.
  • Credentials live only inside the connector that uses them; core-api can check status, never read the secret.
  • The private model runs on your hardware; no ledger data is sent to a public AI API.
All guidesStill stuck? Contact us

More in Plans & security