Skip to slide
Chapter 11 · Security, Auth, and Multi-Tenancy
106 / 191

CHAPTER 11 · Security, Auth, and Multi-Tenancy · 8 / 9

Defense in depth

Layer protections so no single failure is catastrophic:

  • Edge hardening: security headers, CORS locked to known origins, and rate limiting per route class (auth, chat, upload) to blunt abuse and brute-forcing before requests even reach a handler.
  • Input validation: validate request shapes explicitly; never trust client-supplied JSON, ids, or model selections.
  • Auth + authorization: as above.
  • Encryption: secrets at rest, TLS in transit.
  • Least-privilege tools: the model's blast radius is bounded by its tools.
  • Audit trail: the versioned, sourced records (Chapter 9) double as a security log of who/what changed each artifact.

No layer is sufficient alone; together they make the system resilient.

← → arrow keys work too