Tenant and identity foundation
Users can belong to multiple tenant organisations with explicit memberships, roles, entitlements, invitations, session controls, and tenant switching.
- PostgreSQL tenant isolation and RLS where appropriate
- Argon2id authentication and secure sessions
- CSRF, CORS, rate limiting, verification, reset, MFA, and audit