Security posture

Security has three tabs: Isolation states the enforced multi-tenant controls, Runtime covers protection settings, and Notifications routes security events. All three report live status, not a static policy document.

Isolation

Every enforced control (row-level tenant scoping, per-customer compute isolation, cross-tenant egress prevention) is listed with its live status, computed from real enforcement signals rather than a checklist someone fills in by hand. A downloadable isolation attestation summarizes the controls and their test coverage for a security review.

The Security > Isolation tab with each enforced control and its live status
Isolation, stated as evidence: what is enforced, and proof it currently is.

Runtime protection

Runtime protection settings and posture live on their own tab, separate from the static isolation controls, because runtime behavior can change request to request in a way a fixed control list cannot capture.

The Security > Runtime tab with runtime protection settings
Isolation is the architecture. Runtime is what is actually happening right now.

Security notifications

The Notifications tab routes security events - who gets told, and through which channel - separate from the general Preferences notifications, because a security event and a routine product notification warrant different urgency and different recipients.

The Security > Notifications tab with event routing configuration
A security event and a routine ping do not deserve the same inbox.