Tenant isolation
Every private research root carries an owner predicate locally and a forced PostgreSQL row-level security policy in Azure.
Security
Tenant ownership, row-level database policies, hardened sessions, and administrator boundaries protect the research workspace.
Every private research root carries an owner predicate locally and a forced PostgreSQL row-level security policy in Azure.
Session and CSRF secrets are fingerprinted, expiring, revocable, and never exposed through browser-readable account data.
Member accounts are research-only. Shared paper-broker controls, order journals, reconciliation, and arming remain administrator-only.
Administrator access and mutations enter the append-only operational journal with actor and outcome context.
Create a research account or return to your workspace.