Data Handling & Security Architecture
Technical Architecture • Cryptographic Controls • RLS Enforcement
1. Row Level Security (RLS) Architecture
PostgreSQL Row Level Security is active on every relational table in the database schema. Tables default to deny-all. Spouses can only read their own rows and cannot query unlinked military profiles. Only authorized administrative staff holding specific permission tokens may inspect verification documents or leave applications.
2. Document Storage & Signed URL Ephemerality
Files uploaded to verification-docs and application-docs reside in private, unlisted buckets. No public URLs exist. Access is strictly mediated via server-generated cryptographic signed URLs with maximum 300-second lifetimes.
3. WORM Audit Trail Protection
The audit logging architecture enforces Write-Once-Read-Many (WORM) semantics via PostgreSQL triggers preventing any modification or deletion. Every administrative status change, document inspection, and user login is recorded with IP metadata and stored permanently.
