Security

Current controls, without inflated claims.

This page describes controls implemented in the current product. Aishare does not claim SOC 2, ISO 27001, HIPAA, or PCI certification.

Authentication

Supabase Auth manages sessions. Protected application routes require a validated user session.

Workspace boundaries

Organization membership checks and database row-level security protect tenant-scoped data.

Server-side secrets

AI provider, Supabase service-role, worker, Redis, and Creem secrets are not exposed to browser code.

Billing integrity

Creem webhook signatures are verified and event identifiers are used for idempotent processing.

Operational visibility

Sentry and worker heartbeat support can be enabled for failures and queue health.

Data and provider boundaries

Audit prompts and responses may be processed by the selected AI model provider or gateway. Identity and application data are stored in Supabase; billing is processed by Creem. Review the Privacy Policy before submitting confidential or regulated information.

Responsible disclosure

Do not publicly disclose an active vulnerability before a support channel has acknowledged it. The final branded security contact must be configured before production launch.