Trust and security
Security and trust
ClientSupply is operated by Leveriano Habiyambere, ABN 99 286 419 439. This page describes controls that are present in the current application and the limits that remain.
Account and session protection
- Sign-in requires a verified account and a server-created session.
- Passwords, session tokens, invitation tokens and reset/verification tokens are stored as one-way hashes rather than readable values.
- Users can review and revoke active sessions through the Security page.
- Requests are checked against the active organisation and membership on the server.
Workspace and role boundaries
Organisation, owner, manager and staff authority is enforced server-side. Staff access is further limited by assigned work where the workflow requires it. Cross-workspace identifiers receive generic not-found treatment rather than revealing whether a foreign record exists.
Operational evidence
ClientSupply records bounded activity and security evidence for important actions, including access decisions, invitations, workspace changes, progress-note authorship and owner attention. Audit history is not a substitute for monitoring or incident response, and it is not exposed as a raw database stream.
Billing boundary
Private-pilot billing uses bounded Stripe TEST references and server-side commercial authority. ClientSupply does not expose secret keys or raw payment-card data in the browser. Stripe live mode and live payment collection are disabled.
Infrastructure and recovery
The application uses Netlify for hosting/functions and Supabase for the database. The database is configured in ap-southeast-2. Backup and restore procedures are rehearsed separately; an application deletion does not instantly remove every backup copy.
Support access
Support and founder operators do not receive automatic unrestricted access to customer workspace content. The default support posture is deny by default. No general support impersonation console is exposed in the current application.
Incident reporting
Report suspected unauthorised access, wrong-recipient email, tenant-isolation concerns, data loss or other security issues promptly to leveriano@clientsupply.com.au. Do not include passwords, MFA codes, secret tokens, database credentials or full customer exports.
Limits and review
No internet service is risk-free. This page does not claim formal certification, complete attack prevention, guaranteed availability, legal compliance or production readiness. Controls and provider arrangements are reviewed as the pilot changes.