Folvern requires organization membership and scoped Supabase access. Dedicated cross-tenant testing verifies separation before real customer data is introduced.
Security Policy
This draft explains Folvern’s intended beta security posture. It does not claim perfect security, SOC 2, HIPAA, or other certification.
Email confirmation remains enabled, and service-role keys must never be exposed in browser code.
Do not store sensitive regulated data unless compliance requirements have been reviewed by your organization.
Health, database, monitoring, rate limit, security header, and error logging status are visible during beta operations.
Public beta access is founder-reviewed before invitation. Request status and invite status are tracked in the beta pipeline.
Workspace actions, denied access attempts, beta support, exports, and legal acceptance are tracked for operational review where available.
Security is a launch gate, not a marketing claim.
Current controls include Supabase Auth, organization-scoped application access, RLS enforcement, dedicated cross-tenant verification, legal acceptance tracking, security headers, rate limiting, verified production database backup, a separate-target restore drill, and current Storage recovery evidence for the present placeholder-only state.
Broader launch still requires final monitoring/alert routing, security-advisor disposition, incident practice, production email qualification, and legal/security review.
Report suspected security issues through the founder/operator channel during beta. Do not perform security testing against Folvern without written permission.