Security is part of the product, not a footer promise.
SPW is being built with tenant isolation, role-aware access, auditability, and explicit boundaries around server-side processing.
Current controls
- Server-side tenant and permission checks
- OIDC-ready sessions with state and nonce validation
- Tenant-scoped evidence and expiring signed access tokens
- Production secret enforcement, secure cookies, proxy TLS, and migration checks
Object storage encryption, malware scanning, live redaction models, and independent security review are not yet configured.