Security model
Session cookies, bcrypt, app-level row scoping, AES-256-GCM BYOK key encryption, rate limiting, CORS/anti-CSRF for split-origin, and FEATURE_GATING.
Session cookies, bcrypt, app-level row scoping, AES-256-GCM BYOK key encryption, rate limiting, CORS/anti-CSRF for split-origin, and FEATURE_GATING.