Backwrite security boundaries and reporting

The documented security model separates developer SQL access, application user access, and background workload identities.

Developer and workload identities

Developer SQL sessions and background workloads use branch-specific identities. Statement guards restrict sensitive SQL constructs. The provisioner is a separate infrastructure identity; its credentials must not be distributed to applications.

Application authorization

The Data API validates user identity and uses verified claims in parameterized queries. Do not assume a user-supplied session variable or header proves identity. Row permissions and API authorization must be checked for each workflow.

Report a vulnerability

The repository security policy lists security@backwrite.dev for private reports. Include the affected component and version, a minimal reproduction, and the expected impact. Do not publish credentials or exploit details in a public issue.

Discovery is not authorization

The security.txt file provides a reporting contact. It does not certify the deployment, establish a bounty, or grant additional testing permissions. Follow the existing repository security policy and avoid disrupting services.

Related resources