Controls in place
Alignyx Drive uses signed identity context, tenant-scoped service contracts, rate limits, CSRF protections, safe redirects, webhook signatures, and readiness endpoints that fail closed.
- Stripe webhooks require raw-body signature verification and replay protection.
- Postgres readiness checks require representative connection, committed migration state, RLS proof, backup policy evidence, and rollback planning before production approval.
- Health, readiness, and dependency endpoints expose only safe status labels and blocker codes.
- Claim and sign-in reference fields remain untrusted client input; the server validates references, one-time codes, tenant context, and paid status before opening protected workspace access.
- Checkout requests reject client-supplied price, tenant, customer, redirect, and pre-payment dealership intake fields. Stripe session metadata records the server-selected plan and Terms version.