Security
Multi-tenant isolation, private attachments, row-level security, verified billing webhooks, rate limits, and activity history are core system boundaries.
Multi-Tenant Isolation
Organization-scoped data access with row-level security policies enforced at the database level.
Private Attachments
All uploaded files are stored securely with access controls, encryption at rest, and time-limited signed URLs.
Row-Level Security
Postgres RLS policies ensure users can only access data they're authorized to see, enforced by the database.
Verified Webhooks
Billing events are verified using cryptographic signatures before processing subscription changes.
Rate Limiting
API endpoints are protected with configurable rate limits to prevent abuse and ensure fair usage.
Activity History
Key workflow events are recorded with timestamps and user attribution for internal review.
Reporting Boundaries
Incident Ledger supports internal workplace incident documentation. Organizations should review their own reporting, retention, privacy, and access requirements before use.
Questions about security?
Review how Incident Ledger handles incident and evidence records.
View privacy policy