Security
Enterprise-grade data isolation and access control for regulatory product data.
Row Level Security
Supabase PostgreSQL with RLS policies ensuring customers can only access their own organisation data.
Authentication
Supabase Auth with secure session management. Dashboard routes protected via middleware.
Document storage
Private document storage by default. Documents marked public are the only files exposed on passport pages.
Audit logging
All significant actions logged with user, entity, and timestamp for compliance traceability.
Infrastructure
Vercel-compatible architecture with environment-based configuration. No secrets in source code.