Skip to content

Running the business

Security and data handling

Workspace isolation, row-level security and least-privilege access to every record.

Isolation

Every table is protected by row-level security scoped to the workspace, and each client company has a separate record tree. One client's documents can never be read into another client's tender.

Access

Sign-in is by email or Google. Roles are held in a dedicated table and checked server-side; the administration console is restricted to the platform owner.

Storage

Uploaded documents, signatures, signed forms and scanned returnables live in private buckets with workspace-scoped policies. Financial tables are read-only to clients and written only by verified server-side processes.