Is there a wiki for security? It sounds its performance is good to not have a middle layer between interface and database, but then I have no idea how do you apply SQL-injection prevention, rate limit and other QoS.
idk about this thingy but the original PostgREST is not vulnerable to SQL injection. You're not writing SQL, you're writing URL query strings, and PostgREST processes them correctly (I think it uses prepared statements for most things, and careful filtration for table names and such).
pREST is not vulnerable to SQL injection, recommend you run tests