Security & Enclave GovernanceBFF Security Layer Active
Settings & Security Architecture
Zero-knowledge telemetry enclaves, multi-tenant isolation policies, and server-side reverse proxy controls.
Backend-for-Frontend (BFF) Security Status
Public Client → Same-Origin /api/* → Private EnclaveSecret Isolationserver-only GuardedNo NEXT_PUBLIC_ leakage
Anti-IDOR DefenseMulti-Tenant ScopedStrict ownership verification
Input ValidationZod Strict SchemasServer-side boundary
Rate LimitingTiered Token Bucket10-120 req/min limits
Trigger live same-origin proxy handshake through centralized API client:
Zero-Knowledge Telemetry Enclave
Guaranteeing raw source document isolation
FailureOps processes raw PRDs and telemetry within a local, client-isolated cryptographic boundary. Only mathematical vector weights and anonymized failure graphs are permitted to cross project boundaries.
Anonymous Pattern SharingEnabled for collective organizational memory
Raw PII Redaction Filter100% Strict Auto-Redaction
Enclave Storage & Retrospective Retention
Telemetry snapshots are retained for 365 days to continuously calibrate historical mortality models.
Enclave Vector Storage Used:14.2 MB / 1.0 GB