accore
Resources

Security Overview

Kurzfassung Trust & Governance für Entscheider. Formale Zertifizierungen werden hier nicht behauptet — Deep-Dive unter Platform → Security.

  • Access-JWT am Edge: Signatur, exp, iss, aud — keine Rollen-Auswertung im Gateway
  • Tenant-Isolation: Identity global, Domain-Daten regional mit RLS
  • Least-Privilege Service-Rollen (RW/RO) in Shared DBs
  • Append-only Audit je Domain + Request-Korrelation (X-Request-Id)
  • CORS und Rate-Limits am Gateway; grobe Edge-Limits am HAProxy

Primär-CTA führt zum ausführlichen Platform-Security-Deep-Dive.

Raccore Business Operations Platform