Tenant and data isolation
Tenant host checks and organisation identifiers scope workspace access. PostgreSQL row-level security policies are enabled across the schema — every organisation-scoped table carries a policy restricting rows to the requesting user’s organisation, as an independent database-level boundary beneath the application layer. Invoice files use a private storage bucket with organisation-folder access policies.