Rrecordlane

Security is a boundary, not a badge.

Trust boundaries

Browser, API, connector runners, OIDC/SCIM issuer, secret provider, PostgreSQL, optional AI provider, operators, CI, backups, and downstream consumers are separate principals. Connector code runs outside the API process. Workspace identity is server-derived from verified membership.

Logical component boundary diagram

Threat and abuse cases

Controls address token forgery, session theft, cross-workspace identifiers, alternate-surface field disclosure, SSRF, malicious imports, formula injection, resource exhaustion, XSS, stale approvals, job lease theft, audit tampering, and sink replay. Browser identity, RLS, failure recovery, and publication reconciliation have executable integration tests; see the platform matrix for exact scope.

Residual risks

The alpha has no independent penetration test or certification. DNS validation is not yet connection-pinned, a privileged database administrator can rewrite and recompute the audit chain, HA failover and broad concurrent scale workloads remain unexercised, and live vendor connectors are unverified without credentials.

Private vulnerability reporting

Use GitHub private vulnerability reporting on the platform repository when the verified repository setting is enabled. Do not put secrets or exploit details in public issues. If that channel is unavailable, publication remains blocked until the repository owner establishes a private route.