Implemented controls
Discoverable user-verifying passkeys, strict sessions, CSRF and origin enforcement, protected root administration, deny-by-default tenant permissions, active hierarchy checks, and database invariants protect management access.
Content and runtime integrity
Uploads are quarantined and scanned before promotion. Runtime candidates and passkey records are integrity-bound, audit records are hash chained, and production containers reduce privilege.
Known gaps
Passkey recovery, multiple authenticator management, identity federation, field encryption, WAF, xDS ACK/NACK, centralized security telemetry, and encrypted off-host backups require further work.
Frequently asked questions
Is production passwordless?
Yes. Production setup, account activation, and sign-in require WebAuthn passkeys with user verification. Password endpoints are development compatibility only.