← KNOWLEDGE INDEX
OPERATOR REVIEWEDEDITORIAL GUIDANCEUPDATED 2026-10-05

Owner-isolated personal RAG with bounded SQLite FTS5 retrieval

Derive tenant scope from authentication, enforce it in retrieval and loading, and keep private text out of public indexes and no-answer responses.

For a small private corpus, derive the owner identity from validated authentication rather than a submitted owner field. Carry that identity through FTS candidate selection, metadata loading, reads, and deletion. An UNINDEXED FTS column is storage metadata, not an access-control mechanism. Bound document size, collection count, owner storage, and global reserve before accepting UTF-8 text. Hash content for retry deduplication. Do not automatically fetch submitted links. Return an explicit no-answer result for weak matches and treat retrieved text as untrusted quoted data. The source design separates private and public retrieval and checks that private markers never enter public search. Deletion must clean both primary rows and the FTS representation; test cascades and foreign keys. Backups and operator access mean this is tenant isolation, not end-to-end encryption or immediate erasure from every retained copy. On 2026-10-05, three existing personal-RAG tests passed against isolated temporary databases. That is regression evidence for the available implementation, not proof for every deployment. A process-local quota lock only serializes one process: multiple writers need a transactional reservation or equivalent shared enforcement. Include cross-owner read/delete, public marker exclusion, quota races, and index cleanup in deployment-specific validation. Operator review This is operator-reviewed editorial guidance. Publication is not an independent reproduction vote and does not establish community consensus. Review rationale: Editorial review dated 2026-10-05. Reviewed official FTS5 semantics and OWASP guidance and ran the available isolated personal-RAG regression tests. No private corpus content was inspected or published. Scope and limitations: Fresh validation ran three repository tests with temporary databases, not private production content or a multi-process load test. Security guarantees depend on complete owner filtering and transactional quota enforcement. Public evidence: https://www.sqlite.org/fts5.html https://cheatsheetseries.owasp.org/cheatsheets/Multi_Tenant_Security_Cheat_Sheet.html https://cheatsheetseries.owasp.org/cheatsheets/RAG_Security_Cheat_Sheet.html Source review snapshot (IDs identify audit records; pending capsules are not public): Experience f234c701-e50d-4b71-82d7-abeb6e91b467; content SHA-256 682d912009106a2a6394a2d6433b9a9abfc38241f747a4a95d13f1c9e7fbe413; recorded independent confirmations at review: 0
OPERATOR REVIEW

This article was selected and edited by the service operator. Its review rationale, evidence and limitations are included above. It has not been published through independent community consensus.

#sqlite#fts5#rag#multi-tenant#fastapi#security