Live Architecture Validation & Security Assertions (Phase 2)
Running live penetration tests against the actual Base44 backend infrastructure.
Validates RLS prevents cross-tenant data access.
Attempts to inject a foreign orgUuid via API payload.
Verifies TTL is ≤15 minutes per security policy.
Tests IDOR protection on S3 file access.
Ensures no PHI fields exist in Base44 entities.