Skip to content

Security

Security as code, not as claims.

The Sailor skeleton ships with audit logging, tenant isolation, encryption, and permission primitives as installable packages — not slideware.

Built-in capabilities

Each item below is a package in this repository. Audit our source on GitHub.

Tenant isolation

@nebutra/tenant

Request-scoped tenant context (AsyncLocalStorage) plus Postgres Row-Level Security policies for hard tenant isolation at the database layer.

Application-layer encryption

@nebutra/vault

Envelope encryption with AWS KMS for customer secrets. Plaintext never leaves the application boundary; rotation-aware data encryption keys.

RBAC & ABAC

@nebutra/permissions

CASL for in-process role/attribute checks.

Structured audit logging

Integration WIP
@nebutra/audit

Consistent AuditEvent format with actor / action / resource / outcome attribution. Architecture in place; production integration in progress.

Better Auth on Postgres

@nebutra/auth

Session/cookie auth backed by Better Auth, with organization membership and device-flow login wired in — no third-party identity vendor sits between your users and your database.

Secrets at the boundary

env validation + @nebutra/vault

Required env vars validated at process start (Zod schema). Application secrets are decrypted on demand, never persisted to logs.

Compliance posture

We list current state plainly — what is in place today versus what is on the roadmap. No badges we have not earned.

GDPR / UK GDPR data handling
Aligned

DPA available on request. Data subject access and deletion workflows in app.

SOC 2 Type II
On roadmap

Not currently certified. Architecture designed to support SOC 2 controls; formal audit planned.

ISO 27001
On roadmap

Not currently certified. Tracking ISMS scope alongside SOC 2.

HIPAA-ready architecture
Subject to BAA

Audit logging, RBAC, and encryption primitives in place; a Business Associate Agreement is required for covered entities.

PIPL (China)
Supported

China-compatible providers (Bailian, Volcengine, SiliconFlow) supported for in-China data residency.

Need our DPA, a security questionnaire, or a chat?

We respond to security inquiries within one business day. For DPA requests, attach your draft or use ours.