SECURITY
Review before every write
Runrail separates extraction, correction, approval, and destination writes. Server credentials stay on the server, device requests are signed, and subscription access fails closed.
The complete production threat model and tenant-isolation checks remain release gates.