Security architecture

Finance AI security controls you can inspect.

Sebastian's finance AI security architecture uses tenant data isolation by workspace schema, applies row-level security to user-private records, and uses accounting data encryption for selected sensitive fields. Human-in-the-loop accounting controls can pause designated writes before execution.

Implemented controls

The security boundary a buyer can evaluate today.

Tenant schema isolation

Workspace business data lives in a tenant-specific Postgres schema selected by the authenticated request context.

workspace scoped
Membership context

Global identity and workspace membership are resolved before services receive their scoped database handle.

request boundary
Private-record RLS

Row-level security protects user-private tables; workspace-shared finance records remain available to workspace members by design.

explicit scope
Sensitive-field encryption

Agent messages, checkpoints, memory, filenames, and connector credentials use per-workspace AES-256-GCM keys.

field inventory
Agent approval interrupt

Designated write tools can pause execution before the tool runs. The journal tool creates a draft in pending review.

human checkpoint
Evidence integrity

Canonical SHA-256 digests allow stored close source snapshots to be re-verified on the server.

content check
Control boundaries

What this page does not imply.

No certification claim

Sebastian does not present repository controls as SOC 2, ISO, or auditor assurance without documentary proof.

proof required
No universal encryption claim

Per-workspace field encryption protects a defined sensitive-field inventory, not every ordinary finance column.

scoped encryption
No enforced SoD claim

Server-enforced preparer-versus-reviewer identity checks remain an implementation gate.

not yet claimed
No period-lock claim

A durable accounting-period lock and documented reopen workflow are not represented as shipped controls.

implementation gate
Go deeper

See the work up close.

Platform architecture

See how workspace scope, evidence, encryption, and durable agent work fit together.

Close evidence

Inspect source provenance, control totals, content hashing, and server verification.

Finance AI scorecard

Evaluate security alongside provenance, authority, exceptions, and monitoring evidence.

Keep your ERP. Close and plan in one pane.

AI for accounting and FP&A on the ledger you already run. No migration. No rip and replace.

Agents at work · Matching an invoice to its PO line…