security · security
Public security architecture overview
Architecture overview
Architecture overview
SaaS uses tenant-scoped authorization, database RLS, server-side API boundaries, short-lived OAuth codes, PKCE, token rotation, signed webhooks, SSRF-safe delivery, and rate limits. This overview is intentionally high-level; implementation details remain internal and are verified by source and tests.