Security

Auth, governance, and evidence posture

Commercial readiness depends on strong auth flows, tenant isolation, and auditable operational controls.

Identity controls

The platform supports tenant-scoped auth, MFA, MFA recovery, SSO, sessions, refresh-token rotation, and API keys. These controls must be consistent across admin and portal surfaces.

Governance controls

Audit logs, incidents, privacy, retention, step-up enforcement, and permission-scoped operations are part of the expected platform posture.

Launch-critical control contracts

Public mutating auth requests must enforce idempotency, and privileged SSO logout must complete both local logout and upstream provider logout.

Source Documents

  • Launch Audit: docs/auditreport.md
  • Launch Recommendations: docs/recommendations.md