Tenants cannot see each other.
Every tenant table carries the organization, with row-level security enabled and forced, and composite keys that make a cross-organization reference impossible to write.
- A cross-tenant request returns a 404 byte-for-byte identical to a real miss. A 403 would confirm the resource exists.
- The application database role is checked at startup: if it is a superuser or can bypass row-level security, the process refuses to boot.
- A verifier walks every table and every database function and exits non-zero on any violation. Last run: 20 tables, 8 functions, 0 violations.