Security program: building

Controls first. Claims only after evidence.

Amberly starts every control as planned and records direct evidence as implementation and operations mature. It does not claim ISO certification, a SOC 2 attestation, or blanket GDPR compliance.

Tenant isolation
Forced PostgreSQL row-level security and transaction-local organization scope.
Least privilege
Separate app, worker, and migrator roles. Runtime roles cannot create schemas or bypass RLS.
Content minimization
No persisted raw source, full patches, prompts, or model responses.
Provider boundaries
Explicit resource budgets fail closed to Unknown and Hold; metadata-only analytics never receives review content.