Access
Auth and isolated workspaces
Security
Technical and operational controls to reduce data leakage, abuse, and data loss risk.
Access
Auth and isolated workspaces
Abuse
Rate limits by IP and user
Resilience
Planned export and recovery
Every operational query must filter by user or workspace. Relational tables should keep foreign keys, RLS/policies in Supabase, and server-side mutation validation.
The product should support export, operational backups, and consistency audits. Before database changes, migrations must be tested in staging with planned rollback.