SSO via OIDC / SAMLRS256/ES256 signature verification against your own identity provider.
Tenant isolation with RLSPostgres row-level security scopes every query to its organisation.
Tamper-evident audit logA hash-chained audit trail; any edit to history is detectable.
Scoped API keys & OpenAPILeast-privilege keys and a published spec at /api/v1/docs.
Signed webhooks & idempotencyHMAC-signed events and safe retries for financial-grade integrations.
Regional data residencyDeploy to the region your regulator expects, UK, EU, US, MEA or Africa.