Enterprise-grade security architecture with multi-tenant isolation and compliance support.
HS256 / RS256 signing
Includes: user_id, tenant_id, roles, app_ids
Support for Google, Microsoft, GitHub
OpenID Connect compliant
TOTP (Google Authenticator)
SMS (optional)
Role-Based Access Control (RBAC)
Project-Level Permissions
Control who can access/modify processes, credentials, agents
TenantID on all core tables
Global query filters (EF Core)
Extract tenantId from JWT claim
Automatic filtering of all queries
AES-256 encryption at rest
Tenant isolation verified
Tracked Events:
Retention: 7 years (configurable)
Real-time Alerts:
Tools: Application Insights, DataDog, Splunk
| Threat | Risk | Mitigation |
|---|---|---|
| SQL Injection | Database breach | EF Core parameterized queries, input validation |
| XSS | Session hijacking | React escaping, CSP headers, HttpOnly cookies |
| CSRF | Unauthorized actions | CSRF token validation, SameSite cookies |
| Brute Force | Account compromise | Rate limiting, account lockout, MFA |
| Data Breach | Privacy violation | Encryption, access controls, audit trail |
| DoS | Service unavailability | Rate limiting, WAF, load balancing |
| Privilege Escalation | Unauthorized access | RBAC, JWT claims, request validation |