Security
Isolation is a database rule
Hiding a button is not the control. A person in one company must not be able to read another company by changing an identifier in the browser.
Draft for review by qualified counsel before production launch. This page describes how the product is designed. It is not a certification and it is not legal advice.
Tenants
Each customer company is a tenant. Business tables carry that tenant, and PostgreSQL row level security checks membership of the signed-in user. The browser does not get to declare the tenant.
Sign-in
Planned sign-in is Google or Microsoft 365 for an approved email domain, after the company is approved and the user is active. This release does not offer a password. Platform operators are provisioned. They are not created by the public form.
Enquiries
Anyone can submit an enquiry through a database function that validates the fields. That role cannot read the enquiry table. Listing, update, and export are limited to platform operators. An export writes an audit event before the file is returned.
The same email can submit at most five enquiries in an hour. A repeat of the same message within two minutes is rejected. A hidden field that is filled in is discarded.
Files and secrets
Company documents are designed for private storage and short-lived links. The service role key stays on the server. This site sends frame denial, a nosniff header, a strict referrer policy, and disables camera, microphone, and geolocation.