Rainmaker.

Security

Controls that are live today

This page describes implemented controls, not aspirational certifications.

Tenant isolation

Postgres row-level security fails closed when a workspace context is absent. The application role cannot bypass those policies.

Data handling

Enrichment is tenant-scoped, suppression is keyed-hash based, and credentials are referenced through secret or OAuth bridges.

Outbound network safety

Server-side URL ingestion blocks private ranges, pins validated DNS results, and revalidates every redirect.

SOC 2 Type I

Control mapping and evidence collection are in progress. A report will be published only after audit completion.

In progress

Security questions or disclosure: security@foreword.example