SECURITY

Designed around tenant separation and controlled production records.

Fourth Rein separates organization access from Fourth Rein platform administration and keeps privileged operations server-side.

Organization isolation

Row Level Security scopes organization records by membership and permission.

MFA

Organization Owners/Admins and Fourth Rein global administrators use authenticator-based MFA for privileged sessions.

Private storage

Production/customer files stay in private object storage and are accessed with time-limited signed URLs.

Admin separation

The private global-admin application is not linked from the organization product and uses a dedicated platform-admin identity.

Auditability

Production locks, customer approvals, project history and platform-admin actions are designed to retain an accountable record.

Secret handling

Database service credentials, deploy hooks and provider tokens stay in server environment variables, not browser code.