Skip to content

Security model

Session cookies, bcrypt, app-level row scoping, AES-256-GCM BYOK key encryption, rate limiting, CORS/anti-CSRF for split-origin, and FEATURE_GATING.