Security Overview¶
Aksara is an async PostgreSQL application framework that generates multiple surfaces from model definitions, including APIs, schemas, Studio/admin surfaces, AI/MCP tooling, and migration behavior. Because generated surfaces multiply security exposure, Aksara treats authorization, tenant isolation, and AI/MCP boundaries as first-class security concerns.
Current Security Controls¶
- Security diagnostics through
aksara doctor security-check - Strict production diagnostics through
aksara doctor production-check - Central
Principalrepresentation for users, AI/MCP agents, anonymous callers, and system tasks PolicyEnginefor authorization decisions, field visibility, field writability, tenant filters, and payload validation- Runtime payload enforcement for covered generated write paths
- Field-level controls for AI-sensitive and non-agent-writable fields
- Tenant-aware policy checks and tenant-required fail-closed decisions
- MCP credential validation helpers for scopes, audience, tenant binding, expiration, and token metadata
- Studio/MCP production exposure diagnostics
- Bounded adversarial tests for generated surfaces
- Migration safety controls that improve the reliability and integrity of generated schema changes (transactional application, advisory locking, checksum verification of applied migrations, and SQL-generation guardrails)
- Explicit Durable Operations with current authorization, fenced ownership, bounded approval and recovery contracts
- Public security matrix example and strict release-mode matrix enforcement
Generated Surfaces¶
Generated REST routes, serializers, filters, ordering, pagination, migrations, Studio/admin surfaces, AI prompt context, and MCP tool descriptions can all expose security-relevant behavior. Aksara's public security controls focus on server-side policy decisions and runtime checks rather than trusting generated schemas as the boundary.
Current Limitations¶
- Production support is bounded by the v0.7 contract; it is not a blanket claim for Studio or AI/agent features.
production-check --releasealways requires a complete matrix. Deployment checks without--releasekeep missing-matrix findings advisory unlessAKSARA_REQUIRE_SECURITY_MATRIX=true.- Bulk/upsert principal enforcement is helper-level unless integrated by the application path.
- The Streamable HTTP MCP endpoint at
/mcp/provides protocol discovery and execution for generated tools./ai/tools/mcpremains an inspection catalog; it is not a second execution boundary. - No external security audit certification is claimed; the review scope and release evidence are published for assessment.
Recommended Production Workflow¶
- Apply migrations with a migration role.
- Run the application with a restricted role and forced RLS for tenant tables.
- Review generated surfaces and AI-writable fields.
- Run
aksara doctor production-check --releasewith the project's complete security matrix. - Treat passing diagnostics as one prerequisite. Validate application-specific authorization, backup/restore, monitoring, and the selected worker/deployment topology; diagnostics do not certify a deployment.