Separate identity boundaries
Customer sessions and platform-owner sessions use different cookie names and different authentication boundaries. The owner identity uses TOTP MFA and a Strict SameSite owner session cookie. Customer passwords are hashed with scrypt.
Tenant isolation in the database
Tenant operations are executed with tenant/account context, and tenant-owned tables use PostgreSQL row-level security. The normal runtime role does not receive superuser or BYPASSRLS privileges.
Public edge and request controls
The web layer sets security headers, state-changing authenticated requests use CSRF/origin protections, and rate limiting is applied to sensitive/public endpoints. The API is designed for loopback/private access behind the managed public web edge.
Private media pipeline
Original media is stored through a private S3 configuration with public access blocked. The application processes uploaded bytes and serves approved variants rather than publishing arbitrary storage objects directly.
Release checks are part of security
A secure feature can still be lost by a bad release. BADWEB therefore runs contract and unit checks across identity, provisioning, products, pricing, billing, domains/TLS, media and other areas, scans for secrets, and signs release file hashes in a manifest.
