The Neat SaaS Kernel is the running platform: annex an existing RDBMS, pick modular options in the setup wizard, and 70–90% of the SP-driven and ORM-driven API layer is generated — with tenant-isolation proofs, auditable RBAC, and a typed SDK. This is the Developer Edition for internal evaluation and VAPT before the production cut.
T-SQL stored procedures via tsqlcraft, or a DB-agnostic ORM, or both. Register one connection — no view rewrites.
Choose auth lanes, plugins, cache/broker engines and features. The wizard shows per-choice usability guidance and emits a reviewable provisioning plan.
generate_domain scaffolds views, serializers, repository and adversarial tests from SP contracts; OpenAPI → a typed TypeScript SDK.
Cross-tenant IDOR proofs, explicit-deny RBAC, per-lane payload crypto, and an admin gate that stays HTTP-only on localhost.
IsAdminLocalOnly (localhost + HTTP only) and are 404 at the Tunnel;
the origin has no inbound ports. Report scope and rules of engagement are in
deploy/cloudflare/DEPLOY_VAPT_RUNBOOK.md.