Security
Current controls, without inflated claims.
This page describes controls implemented in the current product. Aishare does not claim SOC 2, ISO 27001, HIPAA, or PCI certification.
Authentication
Supabase Auth manages sessions. Protected application routes require a validated user session.
Workspace boundaries
Organization membership checks and database row-level security protect tenant-scoped data.
Server-side secrets
AI provider, Supabase service-role, worker, Redis, and Creem secrets are not exposed to browser code.
Billing integrity
Creem webhook signatures are verified and event identifiers are used for idempotent processing.
Operational visibility
Sentry and worker heartbeat support can be enabled for failures and queue health.
Data and provider boundaries
Audit prompts and responses may be processed by the selected AI model provider or gateway. Identity and application data are stored in Supabase; billing is processed by Creem. Review the Privacy Policy before submitting confidential or regulated information.
Responsible disclosure
Do not publicly disclose an active vulnerability before a support channel has acknowledged it. The final branded security contact must be configured before production launch.