Private document storage
Original files are stored in a private Supabase Storage bucket. Browser access uses short-lived signed URLs rather than permanent public links.
Foldline uses private storage, short-lived access, authenticated server logic and explicit human review. Security controls will continue to be hardened as the MVP moves toward broader production use.
Original files are stored in a private Supabase Storage bucket. Browser access uses short-lived signed URLs rather than permanent public links.
Supabase Row Level Security and authenticated server routes restrict access to account and workspace records.
Service-role and other privileged credentials stay on the server and are not exposed through public environment variables.
Extracted values and checks are treated as review aids, not as automatically trustworthy decisions.
Document processing uses short-lived access to retrieve private files instead of making customer documents publicly addressable.
Pilot requests are stored in a table with no anon or authenticated client access. The founder admin view reads them only after a server-side user-ID allowlist check.
For now, security concerns can be submitted through the contact page. A dedicated monitored security mailbox and responsible-disclosure process will be added before broader production use.