Tenant and process isolation
Forced PostgreSQL row-level policies, scoped transaction context and separate web, worker, webhook, maintenance and migration roles protect customer records and operational boundaries.
Saxum is designed to preserve tenant boundaries, source identity, review decisions and release evidence. This page distinguishes implemented controls from live-deployment and customer proof that still requires external execution.
Forced PostgreSQL row-level policies, scoped transaction context and separate web, worker, webhook, maintenance and migration roles protect customer records and operational boundaries.
Record-bound encrypted secrets and artifacts, secure cookie sessions, scoped expiring service tokens, MFA replay protection and enterprise identity foundations reduce credential and record-transfer risk.
Deterministic quality gates, stale-approval invalidation, two-person review where configured and signed release evidence prevent silent automation from becoming authorization.
Exact dependency inventory, a deterministic SBOM, digest-only container configuration and signing workflows are included. Final wheel hashes and published image attestations remain deployment gates.
Backup, restoration and destructive-drill tooling refuse live source targets. Achieved RTO and RPO must still be measured against isolated off-host systems.
Isolated functional and branch-coverage matrices, source and marketing audits, signed samples, migrations, smoke tests and multi-width browser checks form the local release evidence.
AI suggestions cannot waive findings, approve releases, alter source facts, promote rule packs or authorize provider writes. Manual runs force fresh controls, and changed bound inputs invalidate cached results.
Saxum prepares, reconciles and evidences controlled outputs. The customer retains final credentials, regulated attestations and official-platform submission authority unless a separately authorized provider workflow has passed acceptance.
Source-only tests cannot substitute for these executions.
Hosted PostgreSQL 17 and PostgreSQL 18 cross-role qualification, retained proof for the deployed major, final digest-pinned image build, vulnerability scan, publication, signature and provenance attestation.
Real OIDC, Google, Microsoft and provider credentials, authorized write-back acceptance, revocation testing and off-host destructive recovery with measured RTO/RPO.
Supervised paid pilots, external acceptance, measured intervention time, false-positive rate, straight-through processing and renewal evidence.