版本历史Release History

从数据库原生记忆到统一 Agent 管理平台From Database-native Memory to a Unified Agent Management Platform

版本日期以最终打包日期为准。v4.4.10 是面向全新部署的 Production Profile 基线,不承诺从早期 v4.4.x 客户包原地升级;历史迁移仅用于校验和、顺序、复现与审计。v4.4.8 已撤回。Graph Runtime 核心与授权检查为 Production,其他能力按数据库权威能力矩阵为准。Release dates follow the final packaging date. v4.4.10 is a Production Profile baseline for fresh deployments and does not promise in-place customer upgrades from earlier v4.4.x packages; historical migrations remain for checksum, ordering, reproducibility, and audit. v4.4.8 is withdrawn. Graph Runtime core and authorized inspection are Production; other capabilities follow the database-authoritative matrix.

最近版本Recent Releases

最近五个版本Latest Five Releases

v4.4.152026-09-16

持续工作、明确交接与可追溯的成果复用Continuous Work, Accountable Handoffs and Traceable Reuse

修复三数据库任务状态与步骤关联、Portal 连接和会话恢复。实现工作契约与交接、确切版本的上下文组装、原生任务等来源快照、独立候选审核、签名 Skill 交付和诊断,保持数据库实体化设计。受管 Linux 客户端在协作式安全点切换 Skill,读取与执行均重新核对当前授权。Repairs task-state and step relationships, Portal connections and session recovery across three databases. Implements work contracts and handoffs, exact-version context assembly, native source snapshots, independent candidate review, signed Skill delivery and diagnostics using database entities. The managed Linux client switches Skills at cooperative safe points; reads and execution recheck current authorization.

v4.4.142026-09-11

中文运维文档完善与三数据库发布基线Chinese Operations Documentation and Three-Database Release Baseline

v4.4.14 完成三数据库发布基线复核、中文运维文档补全与部署说明统一,保持已发布功能合同不变。v4.4.14 completed the three-database release baseline review, expanded Chinese operations documentation, and aligned deployment guidance without changing the published feature contract.

v4.4.132026-09-08

三数据库智能问答与治理控制面完善Three-Database Intelligent Q&A and Governance Control Plane

v4.4.13 完成三数据库生产基线验证与 Portal 知识增强问答、Agent 治理控制面完善。v4.4.13 completed the three-database production baseline validation, Portal knowledge-grounded answers, and Agent governance controls with a configured model.

v4.4.122026-09-06

用量计费、协作授权与部署体验完善Usage Accounting, Collaboration Authorization, and Deployment Improvements

修正模型缓存与推理用量的重复计费,完善 DB4A2A 分支的参与者检查、快照校验和接收方读取授权,增强数据库连接隔离与事务一致性。修复非默认端口下的登录会话识别、知识范围表单和部署配置,监控页面按平台治理配置展示运行状态,并统一三数据库 Community 与 Enterprise 版本的中文文档入口。Corrects duplicate accounting for cached and reasoning usage, improves DB4A2A participant checks, snapshot validation and receiver read authorization, and strengthens database connection isolation and transactional consistency. Repairs login session handling on non-default ports, knowledge-scope forms and deployment configuration. Monitoring reflects platform-governed runtime configuration, and Chinese documentation entry points are aligned across Community and Enterprise editions for all three databases.

v4.4.112026-08-31

Linux 运行时隔离、DB4A2A 与三数据库新基线验证Linux Runtime Isolation, DB4A2A, and Three-Database Fresh-Baseline Validation

v4.4.11 在 v4.4.10 全新部署基线上增加本地 Linux 运行时隔离适配器契约:bubblewrap、UID/GID、namespace、只读根文件系统、私有 IPC、默认拒绝网络、资源限制与证据校验;容器、VM、MaaS 与 SaaS 仍按实际落地适配。DB4A2A 通过数据库受控上下文引用和分支溯源降低跨 Agent 数据复制。支持 Oracle、PostgreSQL 与 YashanDB 三种数据库底座。v4.4.11 extends the v4.4.10 fresh-deployment baseline with a local Linux runtime-isolation adapter contract: bubblewrap, UID/GID, namespaces, read-only rootfs, private IPC, default-deny network, resource limits, and evidence verification. Container, VM, MaaS, and SaaS enforcement remains subject to deployment-specific adapters. DB4A2A uses governed database context references and branch provenance to reduce cross-Agent payload copying. Supports Oracle, PostgreSQL, and YashanDB database backends.

展开更早版本Show Earlier Releases
v4.4.102026-08-27

全新部署基线:模型治理、组织知识与管理大屏Fresh Baseline: Model Governance, Organization-aware Knowledge, and Executive Wallboard

v4.4.10 是全新部署基线。它提供可并行启用的直连与平台网关、硬/告警配额、原子预留结算、AES-GCM 有界幂等重放、服务商账单追加式对账、企业平衡成本分摊和签名外部证据;平台外未知直连流量保持 UNOBSERVED。知识范围关联组织结构并覆盖公司公开、组织子树、组织层级和人员/Agent 私有策略,统一约束列表、详情、图与检索。登录后只读大屏展示平台运行态及近 14 日 Token 和成本曲线,主要管理视图采用加宽详情面板。v4.4.10 is a fresh-deployment baseline. It provides coexisting direct and gateway routes, hard/warning quotas, atomic reservation and settlement, AES-GCM bounded idempotent replay, append-only Provider invoice reconciliation, enterprise-balanced cost allocation, and signed external evidence; unknown direct traffic stays UNOBSERVED. Organization-aware Knowledge covers company-public, organization-subtree, organization-level, and Human/Agent-private policies across list, item, graph, and retrieval paths. The authenticated read-only wallboard combines platform runtime with 14-day Token and cost curves, while primary management views use wider detail panels.

v4.4.82026-08-18

已撤回:平台智能体加固Withdrawn: Platform Agent Hardening

v4.4.8 已撤回,仅保留为历史证据,不发布、不交付,也不是受支持的升级源。其未完成的实现不得替代 v4.4.9 或任何受批准的早期基线。v4.4.8 is withdrawn and retained only as historical evidence. It is not published, delivered, or supported as an upgrade source. Its incomplete implementation must not replace v4.4.9 or any approved earlier baseline.

v4.4.72026-08-17

LLM 生命周期可靠性、权限清单性能与管理知识基线LLM Lifecycle Reliability, Capability-Manifest Performance, and Management Knowledge Baseline

v4.4.7 是小规模维护优化版本:强化 LLM Provider Profile 保存、引用安全退役、保存配置探活、返回模型身份校验和健康状态回写;Dashboard 权限清单改为单次实时授权上下文计算,启动加载和配置页面分组、间距保持一致。受保护管理频道修复短响应 SSE 最终增量刷新,平台管理知识进入数据库私有知识库并支持按请求语言返回中英文。该版本不新增数据库迁移。v4.4.7 is a focused maintenance release. It hardens LLM Provider Profile saving, reference-safe retirement, saved-profile probing, returned-model identity checks, and health-state writeback. The Dashboard capability manifest is calculated from one current authorization snapshot, while startup loading and configuration-panel grouping/spacing are standardized. The protected Administration Channel fixes the final SSE delta flush for short responses, and platform-management knowledge is stored as private database knowledge with Chinese or English responses aligned to the request language. This release adds no database migration.

v4.4.62026-08-16

统一人员注册、Portal 会话治理与 Graph 能力姿态Unified Human Registration, Portal Session Governance, and Graph Capability Posture

v4.4.6 将 Portal 与 Dashboard 的注册入口统一到独立注册页,支持姓名、邮箱、手机号的可配置策略,以及与 Agent Enrollment Token 严格分离的一次性 Human Registration Token。Portal 增加每用户连接数限制和单会话页面操作租约;外部身份采用供应商中立的事务与回调契约,身份声明不自动授予权限。Graph Engineering 能力明确标记为 PRODUCTION、CONTROLLED、DISABLED 或 UNAVAILABLE。v4.4.6 unifies Portal and Dashboard registration on an independent page, adds configurable display-name, email, and mobile policies, and introduces one-use Human Registration Tokens that remain strictly separate from Agent Enrollment Tokens. Portal adds per-user connection limits and one-page operation leases per Session. External identity uses provider-neutral transaction and callback contracts whose claims never grant authority. Graph Engineering capabilities expose explicit PRODUCTION, CONTROLLED, DISABLED, or UNAVAILABLE posture.

v4.4.52026-08-15

Graph Run 准入、页面状态恢复与一致操作界面Graph Run Admission, Recoverable Page State, and Consistent Operations

v4.4.5 为新 Graph Run 增加定义版本、运行配置和能力兼容校验;Dashboard 子页面使用受限 URL 状态,刷新、重新登录和直接访问后可恢复位置。登录成功后重新装载当前应用壳,页面操作、刷新控件与概览卡片采用统一响应式布局,避免升级后继续使用旧前端资源。v4.4.5 validates definition version, runtime profile, and capability compatibility before admitting a new Graph Run. Restricted URL state restores Dashboard child views after refresh, re-login, or direct navigation. Successful login reloads the current application shell, while page actions, refresh controls, and summary cards use a consistent responsive layout so an older frontend bundle cannot survive an upgrade.

v4.4.42026-08-14

平台管理控制面与 Admin Agent 自动接入Administration Control Plane and Automatic Admin Agent Admission

v4.4.4 将运行概览与 Admin Agent 管理配置分开,平台原生路径由已有可信 Admin Agent 自动完成新节点接入、身份材料生成与登记,减少人工填写和配置错误;外部 Admin Agent 仍使用独立身份验证与审批路径。平台管理频道继续作为受保护的管理边界,业务 Agent 不得加入。v4.4.4 separates Runtime Overview from Admin Agent management configuration. In the platform-native path, an existing trusted Admin Agent automatically admits a new node, generates identity material, and completes registration, reducing manual entry and configuration errors. External Admin Agents continue through a separate identity-proof and approval path. The protected Platform Administration Channel remains a management boundary that Business Agents cannot join.

v4.4.32026-08-13

安全域治理与旧协作组受控绑定Security Domain Governance and Controlled Legacy-Group Binding

安全域成为频道协作唯一的授权与数据边界,记录用途、密级、责任人、显式人员与 Agent 成员、有效期及原因。频道、消息、提示词、Skill、Tool、API、工作区、图关系和旧协作组均不能自行授予权限;旧协作组只提供候选,必须逐项复核后才可绑定,并且一个旧组最多绑定一个活动安全域。Security Domains become the sole authorization and data boundary for Channel collaboration, recording purpose, classification, owner, explicit Human and Agent members, validity, and reason. Channels, messages, prompts, Skills, Tools, APIs, workspaces, graph relationships, and legacy collaboration groups cannot grant authority; legacy groups provide candidates only, require individual review, and may bind to at most one active Security Domain.

v4.4.22026-08-13

内部开发过渡版本,未发布Internal Development Transition, Not Published

v4.4.2 作为 v4.4.3 前的内部连续开发过渡版本,未在 GitHub 或其他公开渠道发布。其 Embedding 自动化与 Graph Production Profile 的实现已并入 v4.4.3:管理员通过一次模型测试完成向量维度识别,并自动维护 Profile、统一 Contract、默认 Space 与 Binding;API Key 加密保存,归一化规则由平台契约强制执行,知识查询遵循当前主体的授权范围。v4.4.2 was an internal transition during the continuous development leading to v4.4.3 and was not published on GitHub or other public channels. Its automated Embedding and Graph Production Profile work is included in v4.4.3: one administrator model test derives the vector dimension, then the platform maintains the Profile, unified Contract, default Space, and Binding; API keys are encrypted at rest, normalization is enforced by the platform contract, and Knowledge queries follow the current Principal's authorized scope.

v4.4.12026-08-12

受保护平台管理频道与 Admin Agent 可用性控制面Protected Administration Channel and Admin Agent Availability

初始化创建仅限受保护管理员、已启用管理 Agent 与经独立审批 Admin Agent 使用的平台管理频道。生产建议 3 个健康 Admin Agent;互异正整数权重、人数多数和权重多数共同限制机器决策,数据库 Leader 租约、任期和围栏令牌拒绝陈旧写入。升级包经验证、预检、人类审批和认证 Admin Agent 决策后,逐节点排空、迁移、健康回执;运行中的 Agent 在安全点切换 Skill。隔离先撤销平台权限,远程进程终止、NFS、对象存储和统一存储仍需要客户适配器。Initialization creates a Platform Administration Channel reserved for the protected administrator, enabled management Agents, and independently approved Admin Agents. Production recommends three healthy Admin Agents; distinct positive weights plus both count and weight majorities constrain machine decisions, while database Leader leases, terms, and fencing reject stale writes. Verified packages proceed through preflight, human approval, authenticated Admin Agent decisions, and per-node drain, migration, and health receipts; running Agents activate Skills at safe points. Containment revokes platform authority first, while remote termination, NFS, object storage, and unified storage remain customer-adapter responsibilities.

v4.4.02026-08-11

数据库原生 SDD 与受治理软件交付图Database-native SDD and Governed Software Delivery Graph

将 Change、Working Revision、Approved Baseline、Requirement、Scenario、Acceptance Criterion、Task、Review、Gate、Evidence、Resource Lease、SCM Connection 和 Artifact 纳入数据库控制面。OpenSpec 负责 proposal、design、tasks、spec 的导入、导出与兼容校验;执行阶段由数据库中的版本围栏、风险门禁、资源租约和证据链控制。Change, Working Revision, Approved Baseline, Requirement, Scenario, Acceptance Criterion, Task, Review, Gate, Evidence, Resource Lease, SCM Connection, and Artifact are database control-plane objects. OpenSpec handles proposal, design, tasks, and spec import/export with compatibility validation; database version fencing, risk gates, resource leases, and evidence chains control execution.

v4.3.72026-08-10

确定性 Bootstrap 部署与 Embedding Contract 治理Deterministic Bootstrap Deployment and Embedding Contract Governance

针对已准备好的目标库,包内 Bootstrap Deployment Agent 校验清单、执行受约束 SQL、记录脱敏部署证据并在交接后退役,不依赖外部 Agent、`psql` 或 LLM 输出作为部署权限。Embedding Profile、不可变 Contract、Space 与 Binding 统一约束向量写入和检索,支持平台托管、企业直连、企业代理、预计算导入及禁用五种模式;Oracle 与 YashanDB 的 PDB、表空间和高权限基础设施仍由数据库管理员按目标环境准备。For a prepared target, the package-local Bootstrap Deployment Agent verifies its manifest, executes constrained SQL, records sanitized evidence, and retires after handoff. It does not trust an external Agent, `psql`, or LLM output as deployment authority. Embedding Profiles, immutable Contracts, Spaces, and Bindings govern vector writes and retrieval in five modes: platform managed, enterprise direct, enterprise proxy, precomputed import, and none; Oracle and YashanDB PDBs, tablespaces, and privileged infrastructure remain database-administrator responsibilities in the target environment.

v4.3.62026-08-07

平台原生 Agent 初始化与受控业务 Agent 创建流程Platform-native Agent Initialization and Governed Business-Agent Provisioning

初始化过程可直接创建 Platform Admin Agent,Enterprise 额外创建受限的 Compliance Admin Agent,不依赖已有外部 Agent。授权人员可提交业务 Agent 申请,经过审批后创建独立身份和部署记录;外部 Agent 仍可通过 Skill-first 注册。Runtime Worker 使用数据库租约与 fencing,Deployment Adapter 提供本地、远程 Worker、容器和 Webhook 契约,客户虚拟化、SaaS、MaaS 连接器按项目适配。Initialization can create the Platform Admin Agent directly, while Enterprise also initializes a restricted Compliance Admin Agent without depending on an existing external Agent. Authorized humans can request a business Agent; approval creates an independent identity and deployment record. External Agents remain compatible through Skill-first enrollment. Runtime Workers use database leases and fencing, while Deployment Adapters define local, remote-worker, container, and webhook contracts; customer virtualization, SaaS, and MaaS connectors remain project-specific extensions.

v4.3.52026-08-05

数据库权威的平台功能配置Database-authoritative Platform Capability Configuration

管理员可按 POC、分阶段部署和实际使用范围启停平台能力。有效能力由版本包所含能力、数据库实例开关与当前主体权限共同决定;身份、授权、安全、审计写入、Agent、用户与平台配置等安全控制面不可关闭。关闭功能保留已有数据与历史,只阻止新入口及该功能专属的后台工作;所有变更要求原因、版本校验并保留不可变审计记录。Administrators can scope platform capabilities for POCs, phased rollout, and actual use. Effective capability is the intersection of edition availability, the database instance switch, and current Principal authorization. Identity, authorization, security, audit writes, Agents, users, and platform configuration remain mandatory. Disabling a capability preserves data and history while blocking new entry points and capability-exclusive background work; every change requires a reason, optimistic version validation, and immutable audit history.

v4.3.42026-08-04

Agent 合规姿态与受治理配置档案Agent Compliance Posture and Governed Profiles

企业版新增注册凭据证明、不可变配置档案、证据、姿态、发现、整改、限时例外和确定性 Controller。提示词、Skill 描述、API 规范与 Agent 自报均不构成授权边界;受限与隔离通过 Gateway、短期凭据、实例围栏和数据库权威状态执行。独立的 Compliance Admin Agent 当前作为无凭据、待激活的受限系统身份运行,不具备自主模型运行能力。Enterprise adds registered-credential proof, immutable Profiles, evidence, posture, findings, remediation, time-bounded exceptions, and a deterministic Controller. Prompts, Skill declarations, API descriptions, and Agent self-reports never authorize; restriction and quarantine are enforced through the Gateway, short-lived credentials, instance fencing, and database-authoritative state. The independent Compliance Admin Agent is currently a credential-less, pending-activation restricted system identity, not an autonomous model runtime.

v4.4.92026-08-19

三数据库安全回归与管理界面可靠性Three-database Security Regression and Administration UI Reliability

v4.4.9 在 Oracle、PostgreSQL 与 YashanDB 上恢复并重新验证数据库权威隔离,修复频道流式输出、完整平台命令反馈、实体关系图、中文组织架构和合规姿态表达。v4.4.10 已改为全新部署基线,因此这里保留的是历史版本事实而不是受支持升级承诺;v4.4.8 已撤回。v4.4.9 restored and revalidated database-authoritative isolation across Oracle, PostgreSQL, and YashanDB, and repaired Channel streaming, complete platform-command responses, entity graphs, Chinese organization projections, and compliance posture presentation. Because v4.4.10 is now a fresh-deployment baseline, this remains historical release context rather than a supported-upgrade promise; v4.4.8 is withdrawn.

v4.3.32026-08-03

Graph Runtime 运行保障与定义供应链Graph Runtime Assurance and Definition Supply Chain

强化以数据库租约、围栏、运行、检查点和事件为权威的替代实例恢复,增加可验证定义摘要、依赖锁、可选 Ed25519 签名、导入扫描与不受信任 Draft 发布门禁。Dynamic Graph、A2A 1.0.1 与 OTLP 保持默认关闭的预览边界。运行时恢复不等同于数据库集群故障切换、RPO/RTO 或外部系统的 exactly-once 承诺。Hardened replacement-instance recovery around database-authoritative leases, fencing, Runs, Checkpoints, and events, with verifiable definition digests, dependency locks, optional Ed25519 signatures, import scanning, and an untrusted-Draft publication gate. Dynamic Graph, A2A 1.0.1, and OTLP remain disabled-by-default previews. Runtime recovery is not a database-cluster failover, RPO/RTO, or arbitrary external exactly-once claim.

v4.3.22026-08-01

受治理版本化记忆与可运维作业边界Governed Versioned Memory and Operable Job Boundaries

将记忆纳入 Family、不可变 Version、当前指针、关系、快照、候选复核、逻辑不可用与持久作业的完整生命周期。关系图仅投影当前可用版本及必要历史谱系端点;历史节点仅保留可追溯元数据,不自动进入运行上下文,图也不构成授权来源。记忆、分支和循环界面明确区分创建定义、入队、Worker 租约处理与启动运行。Added a complete memory lifecycle with Families, immutable Versions, current pointers, relationships, snapshots, candidate review, logical unavailability, and durable jobs. Relationship graphs project only current usable versions and necessary historical lineage endpoints; historical nodes retain traceability metadata only, never enter runtime context automatically, and graphs never grant authority. Memory, branch, and loop UI now distinguishes defining, enqueueing, Worker lease processing, and starting a run.

v4.3.12026-07-31

图形化组织治理与身份归属对齐Graphical Organization Governance and Identity Alignment

新增规整组织画布、组织/人员/Agent/异常四种视图、责任关系与受治理变更,并在三块敏感工作区标记受保护视图。普通平台账号、Human Principal 与组织人员一一对应,注册审批原子绑定主组织;Agent Enrollment Token 确定归属,bootstrap admin 作为唯一受保护系统账号保留最高管理能力。图形和前端标签不授予权限,服务端组织闭包与安全域共同执行授权。Added deterministic organization canvases, organization/people/Agent/anomaly modes, accountability relationships, governed changes, and Protected View markers across the three sensitive workspace regions. Ordinary platform accounts, Human Principals, and organization people now align one-to-one; registration approval atomically binds primary membership, Agent Enrollment Tokens establish ownership, and bootstrap admin remains the sole protected top-level system account. Diagrams and UI labels never grant authority; server-side organization closure and security domains enforce access together.

v4.3.02026-07-29

统一身份、频道、协作关卡与运行配置Unified Identity, Channels, Collaboration Gates, and Runtime Profiles

加入 Human/Agent Principal、审批控制注册、一次性 Enrollment、权限驱动 UI、受治理频道、协作关卡、实例隔离 Agent Gateway。Production Profile 成为生产建议,Graph Preview 显式受控。Added Human/Agent Principals, approval-controlled registration, one-time Enrollment, permission-driven UI, governed Channels, collaboration gates, and an instance-isolated Agent Gateway. Production Profile is recommended; Graph Preview is explicitly gated.

v4.2.02026-07-25

图工程Graph Engineering

引入版本化 Graph Definition、确定性编译、持久 Run 与 Checkpoint、Worker Lease、Event Inbox/Outbox 和受治理干预。该版本定位为实验分支。Introduced versioned Graph Definitions, deterministic compilation, durable Runs and Checkpoints, Worker Leases, Event Inbox/Outbox, and governed intervention as an experimental line.

v4.1.02026-07-24

企业治理与统一品牌界面Enterprise Governance and Unified Brand UI

增加注册 Agent 准入、资源策略、有限授权、多人审批、职责分离、风险审计、留存、法律保全、证据导出和应急控制,并统一 17 个产品页面。Added registered-Agent admission, resource policy, bounded grants, multi-party approval, separation of duties, risk audit, retention, legal hold, evidence export, emergency control, and a unified 17-view interface.

v4.0.12026-07-22

身份与配置安全加固Identity and Configuration Hardening

Business Agent 独立身份并禁止回退;敏感配置使用 AES-256-GCM,增加持久执行任务、无损 Skill 包和严格版本边界。Independent fail-closed Business Agent identities, AES-256-GCM sensitive config, durable jobs, lossless Skill packages, and strict edition boundaries.

v4.0.02026-07-19

统一源码与数据库适配层Unified Source and Database Adapters

以共享核心和数据库适配层重构六个交付版本,增加 MCP 动态工具、规格版本、DAG 可视化、事件死信、搜索解释、图算法和 Agent 自动恢复。Refactored six deliverables around a shared core and database adapters, adding dynamic MCP tools, spec versions, DAG visualization, dead letters, search explanation, graph algorithms, and Agent auto-recovery.

v3.10.x2026-07

崖山适配、加密与通用属性图YashanDB, Encryption, and Universal Property Graph

形成三数据库六版本,完善每 Agent 密钥、配置加密、离线部署和跨领域属性图。Established the three-database, six-edition matrix with per-Agent keys, encrypted config, offline deployment, and cross-domain property graph.

v3.9.02026-07-05

生态连接层Ecosystem Connectivity

MCP、SSE 流式输出、人工审批、Agent Protocol 与多模型路由。MCP, SSE streaming, human approval, Agent Protocol, and multi-model routing.

v3.7.x2026-06

循环工程Loop Engineering

建立循环生命周期、评估、规格驱动 Loop、任务绑定、多 Agent 编排和事件驱动能力。Established Loop lifecycle, evaluation, spec-driven Loops, task binding, multi-Agent orchestration, and event-driven capabilities.

v3.6.x2026-06

PostgreSQL 双版本与身份分离PostgreSQL Editions and Identity Separation

加入 PostgreSQL Community/Enterprise、Admin/Agent 分离、恢复码、私有 Skill 和企业审计。Added PostgreSQL Community/Enterprise, Admin/Agent separation, recovery codes, private Skills, and enterprise audit.

v3.4–v1.02026-05–06

数据库原生基础形成Database-native Foundation

从知识库与属性图起步,逐步增加统一架构、行级隔离、零信任与数据库原生加密。Started with knowledge and property graph, then added unified architecture, row isolation, zero trust, and database-native encryption.