Isolation
Every enforced control (row-level tenant scoping, per-customer compute isolation, cross-tenant egress prevention) is listed with its live status, computed from real enforcement signals rather than a checklist someone fills in by hand. A downloadable isolation attestation summarizes the controls and their test coverage for a security review.

Runtime protection
Runtime protection settings and posture live on their own tab, separate from the static isolation controls, because runtime behavior can change request to request in a way a fixed control list cannot capture. It catches behavior that only shows up mid-request, so an admin is not relying on a point-in-time check to know the platform is safe right now.

Security notifications
The Notifications tab routes security events - who gets told, and through which channel - separate from the general Preferences notifications, because a security event and a routine product notification warrant different urgency and different recipients. A security event reaching the right person fast is the difference between catching a problem in minutes versus finding it in a weekly digest.
