Server-derived tenant context
The hostname, authenticated identity and active membership are validated together. Client-supplied tenant identifiers never authorize access by themselves.
Security and trust
Vilonexa is being built so identity, authorization, data routing, background work and operations all enforce the same trusted tenant context.
Our approach
Security is designed into shared contracts, resource boundaries, migration processes and operational decisions rather than added only at the interface.
The hostname, authenticated identity and active membership are validated together. Client-supplied tenant identifiers never authorize access by themselves.
The architecture targets isolated tenant databases where practical, with tenant-scoped object paths and fail-closed resource routing.
Platform roles and tenant roles remain distinct. Sensitive administrative actions are time-bound, attributable and auditable.
Canary and cohort rollout, compatibility windows, migration status, pause controls and recovery evidence protect tenant availability.
Health, routing, authentication, migration, backup and audit signals support investigation without exposing tenant business payloads.
Backups and restores are rehearsed. Destructive actions require explicit authorization, retention checks and separate operational controls.