Security planned around tenant boundaries.

This page describes the planned production security architecture. Controls will be implemented, tested and documented during later development stages.

Tenant Isolation

The multi-tenant model is designed to ensure strict logical separation of data. Every row in the database associated with a customer will enforce an organization_id column. We plan to utilize PostgreSQL Row-Level Security (RLS) to enforce these tenant boundaries at the database layer, preventing any accidental cross-tenant data spillage.

Vector embeddings for semantic product search will utilize tenant-filtered pgvector queries, meaning that similarity searches are strictly bound to the requesting organization's workspace.

Access Control & Billing

Access will be governed by role-based limits within each brand workspace. Organizations can provision isolated workspaces for different brands or clients while maintaining a unified, org-scoped billing structure. Users will only see products and generations for the workspaces they are explicitly granted access to.

Private Assets

User-uploaded reference imagery and AI-generated outputs will be stored in tenant-specific private storage paths. Assets will not be publicly accessible by default; downloading assets will require short-lived, cryptographically signed URLs generated upon a valid, authenticated user request.

Provider Security

We integrate with external AI providers to generate content. Communication with these providers will be authenticated using server-side provider keys, ensuring credentials are never exposed to the client application.

These external AI providers may process reference images and text prompts under their respective API enterprise terms, which generally restrict the use of customer data for training public foundation models. Users must ensure they have the necessary rights to upload reference material.

Future Auditability

The platform is planned to include a comprehensive audit history logging system. Key actions, generation requests, asset downloads, and workspace modifications will be recorded to provide administrators with clear visibility into organizational activity.

Data Retention

Organizations will maintain retention and deletion controls. Upon account closure or explicit deletion requests, tenant data, associated database records, and private storage assets will be securely purged according to our planned data-lifecycle policies.

Responsible AI Review & Limitations

Our workflows incorporate automated moderation checks designed to flag or block requests that violate our acceptable use policies, including the generation of non-consensual imagery or illicit content.

Please note: We make no formal certification claims at this time (e.g., SOC 2, ISO 27001, HIPAA). The controls detailed on this page represent the target architectural state for our commercial launch.