Row-Level Security
Tenant and client access rules are enforced in PostgreSQL, not inferred only from routes or hidden controls.
Security overview
ClientFlow OS is designed so a modified URL, record ID, request body, or browser state does not grant access to another organization or client.
Tenant and client access rules are enforced in PostgreSQL, not inferred only from routes or hidden controls.
Owners, administrators, managers, workers, vendors, client admins, and viewers receive deliberately different capabilities.
Files live in a private Supabase bucket and are served only through policies tied to organization membership.
Important creates, changes, approvals, AI actions, archives, exports, and access events are recorded for review.
Database secret keys, Gemini credentials, cron secrets, and email provider keys are never bundled into browser code.
Transport encryption, at-rest encryption, and backups depend on the configured Supabase and Vercel plans.