Identity through Keycloak, not a homegrown login
Authentication is delegated to Keycloak over OIDC. Witness never stores a password.
Trust
Identity, access, audit and recovery, stated as what runs in production today - not what is designed, configured, or aspired to.
Deployed today
Authentication is delegated to Keycloak over OIDC. Witness never stores a password.
Every request resolves the caller's role and scope, then checks it against an explicit policy. The absence of an explicit allow is a denial, not a fallback to permissive behaviour.
The browser session cookie is HttpOnly, marked Secure in deployed environments, and scoped to a single origin. It carries no data a script running on the page could read.
Every recorded action is chained to a hash of the one before it. Altering or deleting a past event breaks every hash after it, so tampering is detectable by recomputation - not by trusting that nobody with database access would do it.
A full, isolated restore drill has recovered real rows from a production backup on disposable infrastructure, destroyed afterward. A backup that has never been restored is a hope, not a control - this one has been exercised.
Not yet
Tenant isolation is enforced in the application/repository layer today. A second, independent database-level layer is planned and not yet built.
Rate-limit configuration exists in the codebase. It is not yet wired into an enforced production control.
No SOC 2, ISO 27001, or equivalent audit has been completed. This page will not claim one until it has.