Tenant isolation
Every tenant table carries a factory ID and a row-level security policy. A query executed in factory A’s session returns zero rows from factory B — verified by test, not by convention.
Furnishi exists because installation data crosses a company boundary every single day. Security is not a page we added at the end.
Every tenant table carries a factory ID and a row-level security policy. A query executed in factory A’s session returns zero rows from factory B — verified by test, not by convention.
Partner-facing screens read from database views that do not contain the identity columns. The data is not hidden late; it is never selected.
The platform console is on its own URL with mandatory two-factor and network allow-listing. It is not linked from the product and is not indexed.
When Furnishi support opens a factory workspace, the tenant sees it in their own audit log with the staff member’s name.
Who changed which field, from what value to what value, at what time, from which address.
Primary and backup storage in an Indian region. No customer personal data is processed outside India.
Point-in-time recovery with a 24-hour restore objective, tested on a schedule.
TLS 1.3 in transit; encryption at rest on database and object storage. Media inherits the same access rules as the record it hangs off.
Six roles, levels L1 to L3, and approval actions that require a fresh authentication.
We will fill it in properly, including the questions where the answer is 'not yet'.