Identity and permissions
Supabase Auth manages sessions. Cookies are HttpOnly, private routes revalidate the user, and each business operation explicitly resolves the active organization and authorized role.
Critical rules are enforced on the server and in the database. The user interface is never treated as a security boundary.
Supabase Auth manages sessions. Cookies are HttpOnly, private routes revalidate the user, and each business operation explicitly resolves the active organization and authorized role.
Business tables enable RLS and sensitive relationships include the organization identifier. Privileged functions validate roles, restrict their surface and cannot be called directly by a hostile client.
Server Supabase, AI, Meta, Chariow, email and VAPID keys remain in the server environment. Webhooks verify signatures and asynchronous workers require a Cron secret.
External operations are idempotent, concurrent processing uses atomic locks, critical limits are enforced on the server or in the database, and sensitive administrative actions feed an append-only audit log.
Do not exploit an issue beyond what is needed to confirm it and do not access third-party data. Select “Security” on our contact form and include reproduction steps and the estimated impact.