Skip to main content
Security & data

Security is the table we set every plate on.

The architecture, the controls, the incident-response playbook — written for security reviewers, not buried in marketing prose.

Architecture

Six pillars, one platform.

The controls we treat as table stakes, not as differentiators.

Tenant isolation

Every business row carries an organization_id and is scoped by Postgres row-level security. A normal Supabase client cannot read across tenants; an admin client bypasses RLS only on server-only trusted paths.

Encryption at rest and in transit

All data is encrypted at rest in managed Postgres and managed object storage. Transport is TLS 1.2+ with modern cipher suites. Backups are encrypted with provider-managed keys.

Strict authentication

Supabase Auth handles identity, with mandatory MFA for org admins. Session cookies are HttpOnly, Secure, SameSite=Lax, scoped to the workspace host. We rotate signing keys and detect anomalous sessions.

Immutable audit log

Every privileged action — publish, review decision, certificate issuance, settings change — is logged with actor, timestamp, and payload diff. Logs are append-only and retained per plan.

Least-privilege access

Our team uses scoped, short-lived credentials. Production access requires hardware-backed MFA and is granted through a just-in-time approval flow. No standing access to customer data.

Network controls

Production runs in isolated VPCs with private subnets for data tiers. Outbound network access is allowlisted. Edge traffic terminates TLS at a managed load balancer with WAF rules.

Compliance

The frameworks we work with.

Where we have certifications, you'll see the artefact. Where we're on the roadmap, you'll see the timeline.

GDPR

EU data protection regulation. DPA available on request.

UK GDPR

UK extension of the GDPR with equivalent protections.

SOC 2 Type II

In progress — audit window opens Q3 2026.

ISO 27001

Roadmap target for 2027.

DPA / SCCs

Standard Contractual Clauses for international transfers.

CCPA

California Consumer Privacy Act — supported via in-product tools.

Incident response

What happens when something goes wrong.

A rehearsed playbook, not a wiki page that was last updated in 2024.

Step 01

Detect

Internal monitoring, customer reports, and an annual third-party penetration test.

Step 02

Triage

Severity rated within one hour of detection. High-severity incidents escalate immediately.

Step 03

Contain

Affected systems isolated, credentials rotated, evidence preserved for post-mortem.

Step 04

Notify

Customers notified within 72 hours where personal data is affected, per GDPR.

Step 05

Resolve

Root cause identified, fix deployed, monitoring heightened for related signals.

Step 06

Post-mortem

Public summary shared within 14 days, with the timeline, root cause, and remediations.

Data residency

Where your data lives.

You choose the region at workspace creation. Migration is available on the Enterprise tier.

EU (default)

Frankfurt region. Suitable for EU-resident participants and most EU/EEA customers.

US

AWS us-east-1. Suitable for US-resident participants and US-regulated workloads.

Custom

Enterprise customers can request a specific Supabase region. Discuss with sales.

Sub-processors

Who handles data on our behalf.

Each is governed by a written data processing agreement.

Sub-processorPurposeRegion
SupabaseManaged Postgres, auth, file storageEU / US
OpenRouterAI generation, translation, ratingUS (configurable)
ResendTransactional emailUS (configurable)
VercelEdge & serverless runtimeGlobal edge
Hosting providerBackground jobs, source extractionEU / US

Report a vulnerability

We pay attention to responsible disclosure.

If you find a security issue, please tell us — we acknowledge within one business day and credit researchers in our public hall of fame.

How to report

  • Email security@setec-millenium.app with a reproduction and an impact assessment.
  • Avoid testing on production data — we have a sandbox you can request.
  • We will not pursue legal action against good-faith research that follows this policy.
  • We acknowledge within one business day, triage within 72 hours, and publish a public timeline once resolved.

Out of scope

Denial-of-service attacks, social engineering of our staff, physical intrusion, and issues in third-party providers we do not control are out of scope. Spam or phishing through the Service should be reported to support instead.

Security questionnaire?

Send us your CAIQ, SIG, or your own spreadsheet.

Standard questionnaires get a 5-business-day turnaround. Custom ones get a human to read them, and a human to answer.

Security & data — Setec Millenium — Setec Millenium