SaaS is open · Start your store for free
All documentation

security · security

ACTIVE

Public security architecture overview

Architecture overview

Architecture overview

SaaS uses tenant-scoped authorization, database RLS, server-side API boundaries, short-lived OAuth codes, PKCE, token rotation, signed webhooks, SSRF-safe delivery, and rate limits. This overview is intentionally high-level; implementation details remain internal and are verified by source and tests.

ACTIVE · 2026-08-21 · docs/security/architecture-overview.md

Help us improve SaaS

We'd like to use privacy-respecting analytics to understand how the platform is used and make it better. No personal data is collected without your consent, and you can change your choice anytime. Read our privacy notice