May 10, 2026
Multilingual RAG
Engineered a Django/PostgreSQL knowledge service that separates customer datasets, embeds multilingual documents locally, and constrains generated answers to authorized retrieval context.
RAG and AICustomer data isolation
- Role
- Backend and ML systems engineer
- Published
- May 2026
- Focus
- RAG and AI / Customer data isolation
- Engineer
- Saaim Abdullah

The risk is not a bad answer. It is the wrong customer's answer.
Delivery and scope in numbers
| Design dimension | Implemented scope | What it demonstrates |
|---|---|---|
| Supported prompt workflows | 6 | Q&A, summary, translation, glossary, extraction, explanation |
| Knowledge ownership | Tenant-associated documents and chunks | Query scope belongs to authenticated identity |
| Embedding provider type | 1 local multilingual E5 path | Source text can be vectorized without an embedding API request |
| Generation provider type | 1 external Gemini path | Only selected context is passed to the generation dependency |
| Principal security gates | 3 — identity, authorization, retrieval scope | Each protects a different part of the lifecycle |
| Persistence | PostgreSQL plus pgvector | Metadata and vectors share a relational model |
| Usage control | Per-tenant quotas | Limit consumption independently from data isolation |
End-to-end architecture
| Stage | Input and operation | Required invariant |
|---|---|---|
| 1. Authenticate | Verify token and resolve caller identity | Never trust a tenant ID supplied merely as user input |
| 2. Authorize ingestion | Accept document for permitted customer | Caller must have rights to write that knowledge base |
| 3. Extract and chunk | Convert supported content to passages | Preserve source and owner for every chunk |
| 4. Embed locally | Apply multilingual E5 encoding | Use compatible preprocessing for documents and queries |
| 5. Persist | Write content, metadata, vectors and tenant relationship | Tenant ownership survives all data transformations |
| 6. Check quota | Count/limit permitted requests | Quota decisions do not bypass authorization |
| 7. Retrieve | Search only authorized vectors in pgvector | Filter by tenant inside retrieval, not after results are returned |
| 8. Generate | Give relevant passages to Gemini | Bound external context to authorized retrieved material |
| 9. Return | Render answer and supporting context | User receives only their own accessible information |
Why PostgreSQL is central to the architecture
Why the embedding and generation models are deliberately separate
Six capabilities, one retrieval discipline
| Workflow | Example use | Key quality check |
|---|---|---|
| Question answering | Ask a factual question about uploaded content | Answer is supported by retrieved passage |
| Summarization | Summarize material in a customer's knowledge base | Important facts are preserved |
| Translation | Transform text across supported languages | Meaning is retained, not invented |
| Glossary creation | Explain domain terms from documents | Terms trace back to permitted material |
| Information extraction | Pull named fields or facts | Missing fields are handled explicitly |
| Explanation | Clarify technical source passages | Readability improves without fabricating claims |
Threat model and design reasoning
| Failure mode | Impact | Architectural response or required verification |
|---|---|---|
Forged tenant_id in request | Cross-customer exposure | Resolve tenant from verified server-side identity |
| Ingestion under wrong owner | Permanent data misclassification | Authorize writes and store immutable provenance |
| Vector search omits owner filter | Foreign chunks enter prompt | Add negative cross-tenant tests on every retrieval path |
| Email domain assumed to imply membership | Unauthorized tenant assignment | Verify organization membership independently |
| Concurrent requests race a quota counter | Usage exceeds intended limit | Use atomic accounting and concurrency tests |
| Prompt injection inside a retrieved document | Model follows untrusted content as instructions | Separate system policy from retrieved source content |
| External generation service receives sensitive text | Unintended data egress | Apply explicit provider/data classification policy |
Key trade-offs
What the implementation establishes
Explore the work




SaaimOpen to full-time roles, contract work, and conversations about things worth building.