Isolation the database enforces.
Most breaches in multi-tenant software are a missing clause in a query nobody reviewed. Most of the controls below are in the schema and the migrations, which is why they hold on the query somebody writes next year.
Encryption at restEnforced
Tenant isolationEnforced
Audit logEnforced
Egress allow‑listEnforced for model calls
Network segmentationIn progress
SOC 2 Type IINot started
Row-level security
Every query runs as a role that cannot see past its own tenant. A forgotten filter returns nothing rather than somebody else’s claims.
A key for each tenant
One tenant’s data is sealed with its own key, and that key is sealed by one we never hold in plaintext.
No patient data leaves without a BAA
A vendor with no signed agreement in the subprocessor table is a vendor the code refuses to send patient data to.
Written once, never edited
Every time a person opens a patient’s case or letter it is recorded append‑only — who, what, when, from where.