Security and compliance

Identity, tenant boundaries, and evidence are first-class architecture.

The public site names the target controls, but production security claims require server-side proof, Zitadel configuration evidence, and ServerOps receipts.

Zitadel OIDC and role mapping are identity prerequisites.

Target / gated

Tenant-scoped APIs must enforce authorization server-side.

Target / gated

Training records, source material, and learner state require retention policy.

Target / gated

Compliance exports are gated until LRS and evidence-store contracts pass.

Target / gated