
Row-Level Security
PostgreSQL row-level security with check conditions supports tenant-data separation at the database layer.
CentaurNexus combines role-based access, tenant isolation, encrypted data paths, audit context and read-back. Production operation for EU customers runs entirely on STACKIT in the EU.


PostgreSQL row-level security with check conditions supports tenant-data separation at the database layer.

Keep actor, time, tenant, target, status and the confirmed target-system result together for supported workflows.

Protect access to the administration layer using tenant Zero Trust signals and a check separated from the login identity.

State region, data paths, tenant isolation and operating responsibility in the agreed service scope.
Security controls are designed to limit impact and keep operational responsibility explicit.
Use hardened sessions, CSRF protection, refresh-token rotation and optional MFA for privileged access.
Apply server-side validation, authenticated routes, security headers, rate limits and structured logging.
Use database-enforced row-level security and encryption for sensitive fields.
Show a write as successful only after actual target-system effect and read-back.
CentaurNexus provides technical operating and change evidence. Suitability for a specific regulatory or contractual purpose must be assessed in that context.
Connect roles, permissions and configured approvals to a tenant and responsible actor.
Apply the concrete approval and authorization path for the selected workflow.
Record status, target-system effect, read-back, source, data age and coverage where applicable.

The patent-pending CentaurNexus method uses Zero Trust signals from the customer tenant and a check separated from the login identity to protect privileged access. NexusAgent adds endpoint signals required for supported CentaurNexus workflows to the ZDX context.
Role-based access and explicit operating boundaries make safer actions practical.

Role limits, tenant boundaries, source context and verified outcomes support decisions without hiding responsibility.
Bring one recurring operating situation. We will map the roles, required context and appropriate demo path.
CentaurNexus uses role-based access and PostgreSQL row-level security with check conditions to support tenant-data separation.
Read-back confirms the observed target-system state after a supported write. The action is not shown as successful before that confirmation.
No blanket conformity or certification claim is made. Technical evidence must be assessed against the concrete regulatory and contractual context.
For EU customers, production operation runs entirely on STACKIT in the EU. Further data paths are described in the applicable contractual and privacy documents.