Tenant-aware
by default.
Organizations, roles, service accounts, gateway keys, provider configuration, policies and security events are isolated by tenant context.
Security model / Controls + boundaries
We distinguish implemented controls, design decisions and external validation. CI evidence is not called a certificate, and a penetration test is not complete without an independent report.
Baseline controls operate inside the on-premise environment and are covered by regression tests.
Organizations, roles, service accounts, gateway keys, provider configuration, policies and security events are isolated by tenant context.
The goal is to block known defect classes and produce reproducible evidence artifacts.
Bandit, pip-audit and Trivy for source, dependencies, configuration and container images.
Tenant boundaries, unsafe regex, Unicode DLP bypass, fuzz corpus and gateway policy behavior.
CycloneDX SBOM, checksums, source archive and a keyless-signed evidence bundle for the source snapshot.
Engineering maturity and compliance with specific requirements are different tasks.
| Claim | Status | Accurate wording |
|---|---|---|
| Independent penetration test | Not complete | Scope is prepared; an authorized provider, report and Critical/High retest are still required. |
| Bank certification | Not claimed | Requirements mapping and certification work are defined under a separate scope. |
| Prompt injection coverage | Risk reduction | Guard reduces risk and explains signals; 100% detection is not promised. |
| Tamper-proof audit | Checksum | An event checksum detects changes during comparison, but it is not an immutable chained ledger. |
| HA / DR | Design only | Recovery runbooks and scaling design exist; customer RTO/RPO still require validation. |
Do not send real secrets, personal data or production prompts in the initial email.
The pilot defines the threat model, data classes, fail modes and an independent validation gate.
Discuss a security pilot →