Accounts
- Sign-in is handled by Supabase Auth. Passwords are hashed and never stored in plain text.
- New accounts must confirm their email address before signing in.
- Repeated sign-in and sign-up attempts from the same network address are limited.
- Public forms include automated spam checks.
Data isolation
- Every database table and file bucket uses row-level security, so a signed-in user can only read or change their own organization's records and files.
- Uploaded files are stored in a private bucket and shared only through short-lived links.
- Uploads are checked by their actual contents, not just their file name.
- Privileged database and AI keys are never sent to the browser.
In transit and at rest
- All traffic uses HTTPS, with HTTP Strict Transport Security enabled.
- Data is encrypted at rest by our database and storage provider.
- A strict Content Security Policy allows only our own scripts, each marked with a one-time code, which blocks injected scripts.
- Pages send security headers that block framing by other sites, stop content-type sniffing, limit referrer data, and switch off browser features we don't use.
Current limitations
- The service has not yet had an independent security audit.
Reporting a vulnerability
If you find a security issue, please email us before sharing it publicly.
Contact
Questions about this page? Email info@establis.org.