Security & compliance

Safe by construction, not by instruction.

Every automation we build is engineered so that when it is unsure, it asks a person; it never guesses with your money or your customers. The properties below are enforced in code and in the database, and TenantOps runs on every one of them.

Authority tiers

Every action is classified T0–T4. Reading is autonomous; committing and spending require recorded human authorization. The automation cannot spend money or make legal commitments on its own.

Customer isolation by the database

Row-level security in Postgres means one customer cannot read another’s data, even with a deliberately unfiltered query. Isolation is enforced where a bug cannot reach it.

Append-only memory

Records are immutable and attributed. Corrections are supersessions, not edits, so the audit trail of what was promised and when is continuous.

Data minimization

Automations keep the operational facts they need, not private details. No payment-card numbers, SSNs, immigration status or medical diagnoses, by design and by validation.

Rules for where you operate

Rules are set per customer and per location, so notices, consent and record-keeping follow the requirements where the work happens. Each TenantOps portfolio carries its own law and language pack.

Resilient, vendor-agnostic

Automatic failover across models and providers keeps the automation answering when one vendor degrades. A call at 3 a.m. does not depend on one provider being healthy.