Security approval pack

Security Overview

Draft security posture for tenant isolation, billing safety, readiness gates, and incident handling.

Draft for approval

This page is prepared for launch review. It should not be treated as final legal, privacy, security, billing, or support advice until the matching approval reference is recorded.

Controls in place

Alignyx Drive uses signed identity context, tenant-scoped service contracts, rate limits, CSRF protections, safe redirects, webhook signatures, and readiness endpoints that fail closed.

  • Stripe webhooks require raw-body signature verification and replay protection.
  • Postgres readiness requires representative connection, migrations, RLS proof, backup policy, and rollback evidence.
  • Health, readiness, and dependency endpoints expose only safe status labels and blocker codes.

Incident handling

Severity rules prioritize security, privacy, tenant isolation, billing overcharge, and product availability. Each incident needs an owner until containment and resolution evidence are attached.

Limitations

This overview is not a certification report. Formal security review, customer questionnaires, and penetration testing should be handled as separate approval evidence.