The Application-Layer WHERE Leak
In naive multi-tenant systems, tenant filtering is left to application code. A single missing WHERE tenant_id = ? clause in a reporting query or microservice leaks competitors' private pricing and customer lists. We enforce tenant boundaries strictly in the PostgreSQL kernel via Row-Level Security (RLS).
CRITICAL RISK