Security

Designed around hostile uploads and sensitive acquisition data.

Every uploaded file is treated as untrusted. The platform is structured for quarantine, validation, immutable logs, access control, secret masking before AI, and future migration to isolated Google Cloud workers.

Upload Quarantine

SQL dumps, CSVs, archives and code packages are stored outside public web access and must pass validation before processing.

Immutable Logs

User, analyst, AI and admin actions are recorded for accountability and forensic review.

Access Control

Plans, roles, permissions, sessions and security events are separated into dedicated tables and services.