Workspace isolation
Projects, evidence, responses and exports are scoped to authenticated workspace membership, with database row-level policies as an additional boundary.
Current security, tenant-isolation, source-storage and response-governance controls in the Sefixa hosted private pilot.
Projects, evidence, responses and exports are scoped to authenticated workspace membership, with database row-level policies as an additional boundary.
Retained original evidence is stored privately and downloaded through authenticated no-store application paths rather than public source URLs.
Hosted sessions use rotating HttpOnly cookies, provider-side validation and recovery behavior for stale or invalid credentials.
Key uploads, project actions, review decisions, exports and retention changes are recorded for workspace governance.
Persistent rate limiting, request identifiers, structured runtime logging and security headers support production operation.
SAML SSO mapping and SCIM provisioning paths exist; actual availability depends on configured identity-provider and underlying platform support.
Sefixa can require review for unsupported or stale-evidence responses and can block exports that do not meet configured approval conditions.