Tenant-scoped data access
Organization membership and row-level security restrict queries to the active tenant context.
Zypta combines application authorization with storage-layer tenant controls. The interface explains access; the service enforces it.
Customer records live in a multi-tenant system with organization context and row-level policies governing access. We do not describe this as a separate database per customer.
Members, app entitlements, files, messages, records, and public resources are resolved through Organization A's context.
Organization B uses the same service plane but cannot satisfy Organization A's membership and row-level access policies.
Organization membership and row-level security restrict queries to the active tenant context.
App access is checked at shared middleware and at ownership-aware public entry points-not only in the interface.
The staff console uses a separate database, signing secret, session type, and role model from customer authentication.
Public links and shared resources are checked against their owning organization before content is returned or changed.
Organization changes, staff entitlement overrides, and bundle assignments produce durable audit records.
When licensed access ends, supported apps move through a time-limited read-only state before denial.
This page describes controls implemented in the product today. Formal certifications and external attestations will be published only after they have been completed.
Read the privacy noticeCreate a workspace, start with the bundle that fits today, and keep your add-ons when your needs change.