Tenant isolation
Stateful queries carry an organization boundary. Server-side authorization protects decisions, policies, approvals, exports, connections, and administration.
Review how Endram isolates organizations, controls identity, preserves policy and decision history, brokers integrations, and restores state before it enters an agent’s production path.
Stateful queries carry an organization boundary. Server-side authorization protects decisions, policies, approvals, exports, connections, and administration.
Sessions are hashed, HTTP-only, SameSite, expiring, and revocable. Google OAuth tokens are verified against issuer signing keys.
OIDC supports Authorization Code with PKCE and JWKS validation. SAML 2.0 validates signed assertions and audience/domain binding. Both support forced SSO and role mapping; SCIM supports revocable provisioning.
Published policy versions and authorization decisions keep the actor, target, result, reason, and timestamp required for review.
Stripe webhooks are signature-verified and replay-protected. Composio holds provider authorization while Endram stores workspace-scoped connection identifiers.
SQLite runs in WAL mode with integrity checks. Backups support independent encryption, off-box storage, and restore verification.
The deployment supports a non-root container behind TLS, read-only filesystems, dropped capabilities, health checks, and resource limits.
Endram does not claim independent certification without current evidence. Implemented controls and current boundaries are stated directly.
Start in shadow mode, review the decision record, and publish a policy only when its effects are understood. Procurement reviewers can use the linked trust and legal documents.