Security
Owner boundaries are part of the product.
This first slice uses Supabase Auth, PostgreSQL row-level security, server-validated inputs, and owner-derived database operations.
Implemented in the development build
- Authenticated owner checks on private product tables.
- No service-role credential in browser or mobile code.
- Atomic assignment economics writes and database-owned audit events.
- Secure response headers and refreshed server sessions.
Required before public launch
A hosted-environment review, recovery drill, dependency scan, incident contact, and disclosure process remain manual launch gates. This page does not claim a certification or independent audit.