SECURITY

Security is enforced through identity, tenant boundaries, entitlements, and governed actions.

This page describes the current Public Beta security posture. It is a technical overview, not a certification or contractual security schedule.

ACCESS CONTROL

Authenticated and organization-scoped.

  • Supabase Authentication protects customer access.
  • Organization membership is validated before protected workspace access.
  • Owner-only management paths enforce role-aware checks.
  • Password recovery uses single-use authentication links and PKCE session exchange.

DATA ACCESS

Tenant-aware database enforcement.

  • Row Level Security policies scope supported data access to the active organization.
  • Commercial catalog writes are restricted and governed mutations are server-controlled.
  • Pending commercial entitlements cannot use activated product capabilities.
  • The public Demo uses synthetic fixtures and does not expose production tenant data.

AI GOVERNANCE

AI authority is bounded by product controls.

  • Agent roles include authority and risk boundaries.
  • External actions remain locked by default in the Public Beta.
  • Approval-requiring work is designed to stop at a human decision boundary.
  • Traceability links intent, evidence, meetings, decisions, approvals, and actions.

CURRENT LIMITS

Public Beta is not a security certification.

  • No SOC 2 or ISO 27001 certification is currently claimed.
  • Enterprise use should undergo customer-specific security and data review.
  • Do not treat the public Demo as a place for confidential or production information.
  • Security controls and documentation may be strengthened during the Beta.

SECURITY REPORTING

Found a security issue?

Do not include passwords, access tokens, private keys, or unrelated customer data in an initial report. Provide the affected URL, reproduction steps, expected behavior, and observed behavior.

Report responsibly

Email Security

security@rythm-os.com