Security
Every account arrives by invitation, every change is recorded, and every permission is checked on the server. Here is exactly what that means.
Permissions are data, not code branches. Every company starts from the same default grid and can change any cell of it — for its own organisation only, and without waiting for a release.
The question of who is allowed in is answered once, in one place, before an account exists. Nobody is admitted first and sorted out afterwards.
Two layers, deliberately. The cheap check runs at the edge on every request; the real one runs against the database before anything is rendered.
The log is not a debugging aid that happens to be visible. It is a first-class screen, built to answer the question an auditor actually asks: who changed this, and what did it say before.
Nothing exotic, and that is the point: a standard managed Postgres, queried the one safe way, with the genuinely sensitive fields encrypted before they are stored.
Set once, at the edge, for every route the application serves — so a new page cannot arrive without them.
If your IT team has a review process, we would rather answer it properly than have you guess from this page.
Talk to us