Tenant boundaries
Every server and repository operation carries tenant context; identifiers alone never grant access.
Tenant isolation, default-deny permissions, restricted workspaces, append-only evidence and fail-closed safety paths are built into the operating model.
Every server and repository operation carries tenant context; identifiers alone never grant access.
Medical, counselling, discipline and custody details use separate authorization and are excluded from broad search/cache.
This foundation does not claim certification or legal compliance. Production gates and residual risks remain explicit.