Skip to content
Architecture-Backed Security

Enterprise-grade student data isolation & zero compromise

Every technical claim we make is implemented in the database and service source code. No marketing buzzwords—just cryptographic isolation and hardened microservice boundaries.

PostgreSQL FORCE ROW LEVEL SECURITY

Postgres RLS is forced on every tenant table. Queries execute inside transactional scopes (set_config('app.current_tenant')), guaranteeing that one institute can never read or mutate another institute's records.

Code Proof: infra/postgres/init/002_rls.sql

Gateway Trust Boundary

The API gateway is the single JWT verifier. All client-supplied identity headers (x-tenant-id, x-user-role) are stripped on arrival and replaced with verified claims before proxying.

Code Proof: services/api-gateway/src/identityHeaders.js

Opaque Rotating Refresh Tokens

Refresh tokens are 64-character opaque strings hashed with SHA-256 at rest. Every token use revokes the previous token and issues a new pair to prevent replay attacks.

Code Proof: services/iam-svc/src/tokens.js

Rate-Limited Edge Protection

Strict brute-force rate limiters (20 req / 15 min) guard all authentication and checkout endpoints, protecting against automated credential stuffing.

Code Proof: services/api-gateway/src/server.js