Security overview

A plain-English summary of what's in place today. This describes the current implementation only — nothing here is a certification and nothing overstates what the app does.

Data isolation

Every application table has an organization_id column and row-level security policies keyed on it. Users can only see and touch rows belonging to organizations they're a member of. Cross-tenant isolation is verified by an automated test suite that runs as two separate signed-in users against the real database.

Roles and permissions

Six roles: owner, admin, manager, employee, contractor, client. Every server action rechecks the caller's role before touching data; the browser is never trusted for permissions.

Authentication

  • Email + password, minimum 8 characters.
  • Session cookies are httpOnly and set with the platform's security defaults.
  • Rate limits on sign-in, sign-up, and password reset — per IP and per email.
  • Password reset and email changes require re-authentication with the current password.

Network / URL handling

The audit feature fetches URLs you supply from our servers. To prevent server-side request forgery (SSRF), we allow only http/https, resolve DNS, and reject private, loopback, link-local, cloud-metadata, and IPv6-mapped-IPv4 addresses — both on the first request and after any redirect.

AI content

AI features are optional and off by default. When enabled, we send only structured findings and line items to the model — never raw HTML or page contents.

Transport and secrets

The app is served over HTTPS in production, with strict security headers (HSTS, frame denial, referrer policy, MIME sniffing off). Secrets live in environment variables — never in the source tree — and are not shipped to the browser.

Backups

Backups are provided by the underlying database vendor (Supabase). We do not currently offer a separate customer-visible backup guarantee.

Reporting a vulnerability

If you believe you've found a security issue, please contact the account owner of your Volkri organization directly rather than posting publicly.