Multi-Tenant Isolation
Complete data and authorization boundary isolation per tenant with PostgreSQL schema separation
Policy-Based AuthZ
JSON-based policy engine with fine-grained permissions, resource-level control, and inheritance
JWT Authentication
Stateless JWT tokens with secure signing, configurable expiry, and refresh capabilities
gRPC + REST APIs
High-performance gRPC backend with HTTP/REST gateway for maximum flexibility
Email Verification
Resend integration with customizable templates, welcome flows, and OAuth support
OAuth SSO
Google OAuth integration with extensible provider framework (GitHub, Azure AD ready)
Audit Logging
Comprehensive audit trail with centralized logging service and queryable history
Billing Integration
Stripe-based subscription management with usage tracking and tiered plans