Security
Security boundaries before automation.
SAM is being designed around tenant isolation, permission checks, protected server-side actions, and an auditable history.
This preliminary content is provided for product development and must be reviewed before public launch. Legal, privacy, security, tax, and regulatory requirements vary by jurisdiction.
Architecture principles
- Every private record belongs to an organisation.
- Members receive the minimum role and data access they need.
- Secret keys and service-role access remain server-side.
- AI actions must pass permissions and high-risk approval checks.
- Customer messages must not be exposed through public database access.
Current status
The repository includes tenant-scoped row-level security, protected server routes, origin and token validation, rate limits, idempotency and grounded-response controls. Production deployment and independent assessment remain separate operational steps. SAM in a Box does not claim certification or universal legal compliance.
Regional requirements
Security, privacy, data location, retention, and regulatory requirements vary by jurisdiction and customer context. They require professional review before launch.