Backwrite security boundaries and reporting
The documented security model separates developer SQL access, application user access, and background workload identities.
Developer and workload identities
Developer SQL sessions and background workloads use branch-specific identities. Statement guards restrict sensitive SQL constructs. The provisioner is a separate infrastructure identity; its credentials must not be distributed to applications.
Application authorization
The Data API validates user identity and uses verified claims in parameterized queries. Do not assume a user-supplied session variable or header proves identity. Row permissions and API authorization must be checked for each workflow.
Report a vulnerability
The repository security policy lists security@backwrite.dev for private reports. Include the affected component and version, a minimal reproduction, and the expected impact. Do not publish credentials or exploit details in a public issue.
Discovery is not authorization
The security.txt file provides a reporting contact. It does not certify the deployment, establish a bounty, or grant additional testing permissions. Follow the existing repository security policy and avoid disrupting services.