GetFlowly IA
Verifiable trust

Platform security

Critical rules are enforced on the server and in the database. The user interface is never treated as a security boundary.

Identity and permissions

Supabase Auth manages sessions. Cookies are HttpOnly, private routes revalidate the user, and each business operation explicitly resolves the active organization and authorized role.

Multi-tenant isolation

Business tables enable RLS and sensitive relationships include the organization identifier. Privileged functions validate roles, restrict their surface and cannot be called directly by a hostile client.

Secrets and integrations

Server Supabase, AI, Meta, Chariow, email and VAPID keys remain in the server environment. Webhooks verify signatures and asynchronous workers require a Cron secret.

Resilience and traceability

External operations are idempotent, concurrent processing uses atomic locks, critical limits are enforced on the server or in the database, and sensitive administrative actions feed an append-only audit log.

Report a vulnerability

Do not exploit an issue beyond what is needed to confirm it and do not access third-party data. Select “Security” on our contact form and include reproduction steps and the estimated impact.