Security by architecture

Documents are sensitive. The product is designed around that assumption.

Foldline uses private storage, short-lived access, authenticated server logic and explicit human review. Security controls will continue to be hardened as the MVP moves toward broader production use.

Private document storage

Original files are stored in a private Supabase Storage bucket. Browser access uses short-lived signed URLs rather than permanent public links.

Database isolation

Supabase Row Level Security and authenticated server routes restrict access to account and workspace records.

Server-only credentials

Service-role and other privileged credentials stay on the server and are not exposed through public environment variables.

Human review

Extracted values and checks are treated as review aids, not as automatically trustworthy decisions.

Bounded file access

Document processing uses short-lived access to retrieve private files instead of making customer documents publicly addressable.

Private pilot inbox

Pilot requests are stored in a table with no anon or authenticated client access. The founder admin view reads them only after a server-side user-ID allowlist check.

Security contact

For now, security concerns can be submitted through the contact page. A dedicated monitored security mailbox and responsible-disclosure process will be added before broader production use.