Security
Security by default, not by bolt-on.
Khwand was built multi-tenant from day one. Company data is isolated across three layers, and every AI action is auditable.
Isolation
Three layers of tenant isolation.
Defence in depth — a breach of any single layer cannot expose another company's fleet.
Tenant isolation at the application layer
Every record in the system carries a tenant ID. Tenant-scoped repositories enforce it on every query — no caller-supplied tenant ID is trusted.
Tenant-aware services
A TenantContext is threaded through every tenant-bound service, so the business logic can never silently cross company boundaries.
PostgreSQL row-level security
The database is the final isolation boundary. RLS policies use a transaction-local tenant setting, and composite keys prevent cross-company relationships.
Practices
How we keep the fleet data safe.
Least-privilege credentials
Production API credentials are least-privilege, non-owner, and cannot bypass row-level security policies.
Full AI audit trail
The AI action log records every decision with reasoning, confidence, action and timestamp — a complete, inspectable trail.
Role-based access
Company owner, operations manager, maintenance manager and workshop partner — each role only sees what it is entitled to.
Modern authentication
Clerk-powered authentication with organisations and roles, integrating with backend authorisation.
Put an AI employee on your fleet. Starting at £10 a vehicle.
Join the early access programme and let Khwand monitor, maintain and optimise your vehicles — no hardware required.