Security & IAM Checklist¶ [ ] Least-privilege IAM per service. [ ] KMS encryption; key policy reviewed. [ ] VPC endpoints (if required); TLS enforced. [ ] Tenant isolation via PK namespace or per-tenant tables.